Each file or directory processed by the Open Computer Forensics Architecture has a set of attributes that combine into a unique identifier.
- The name of the investigation (case)
- The name of the evidence source (source, mostly a name on a tag or label) within the investigation.
- The name of the specific item within the source. This could be the 1st SATA disk from a PC, the 21th DVD from a spindel of data DVD's etc.
- The id of the directory or file within the item.
The case/source/item triplet is often used as an Item or ItemIdentifier object. Together with the evidence id, the combined four are often used in an EvidenceIdentifier object.