Computer & Hard Drive Forensics
Volatile memory capture, encrypted volume access and deleted file carving from workstations, servers and storage media.
What the machine did, and when
Computer forensics answers questions a user cannot: what was copied to that USB device, what was accessed the night before a resignation, what was running in memory when the incident occurred, what was deliberately deleted and when.
Acquisition is performed to a forensically sound standard, from the drive image through to volatile memory and hibernation files. Encrypted volumes including BitLocker and FileVault are addressed where authorization exists.
What we deliver
Volatile Memory & Hibernation
RAM and hibernation file capture preserving evidence that disappears at shutdown.
Encrypted Volumes
BitLocker and FileVault volumes addressed where lawful authority has been established.
Deleted File Carving
Images, video and documents recovered from unallocated space and file system remnants.
OCR & Keyword Triage
Transcription, OCR and keyword indexing across recovered material to find what matters.
How a drive is actually acquired
The examination never touches the original. A hardware or software write blocker prevents any change to the source, a complete bit-for-bit image is taken, and cryptographic hashes are calculated at acquisition and verified afterwards so that any alteration would be detectable by anyone who checks. The original is sealed and stored; every subsequent step happens on the verified copy.
Where the machine cannot be shut down — a production server, a system holding volatile evidence, a drive whose encryption key exists only in memory — a live acquisition is performed instead, with the actions taken and their effect on the system documented contemporaneously. Live acquisition is not a shortcut; it is a considered decision with its own record, and an examiner who cannot explain why they chose it has a problem.
Encryption is where cases are won and lost before analysis begins. A powered-off machine with full-disk encryption and no key, no recovery key and no credential is, for practical purposes, a brick. A machine that is running and unlocked is an entirely different proposition. That is the single strongest argument for calling before anybody powers something down.
What a disk actually remembers
Most people picture forensics as recovering deleted files. That is part of it and rarely the important part. The important part is the record a computer keeps of what a person did, which is far more extensive than users realise.
File system records retain creation, modification and access times, and the change journal often shows activity for files that no longer exist.
Registry and system artefacts record which USB devices were connected and when, which folders were browsed, which documents were opened, which applications were run and how often. For a departing-employee case, USB connection history alone frequently answers the question.
Shortcut and jump list artefacts survive the files they point to, showing that a document existed on a removable drive even when the drive is long gone.
Execution artefacts show what ran, when and from where — including portable applications launched from a USB stick and never installed.
Event logs record logons, sessions, service activity and errors, and often the exact clock.
Browser and webmail traces show searches, uploads to personal cloud storage and webmail attachments — the modern route data actually leaves by.
Cloud client artefacts from synchronisation applications record which files synchronised to a personal account and when.
Shadow copies, hibernation and page files preserve older states of the system, and frequently contain material the user believes was deleted.
Unallocated space holds recoverable fragments of deleted content — sometimes.
The limits, stated honestly
Solid-state drives change what is recoverable. Modern SSDs actively clear blocks marked as deleted, as a normal part of maintaining performance, and this happens without user involvement. On an SSD that has been powered on since a deletion, deleted file content is frequently unrecoverable — not because the examiner lacks skill, but because the drive erased it. Anyone promising routine deleted-file recovery from an SSD is overstating it. Metadata and artefacts about the deletion often still survive, and are frequently sufficient.
Overwritten is gone. Data that has been overwritten by new content is not recoverable, by anyone, with any tool. There is no laboratory technique that recovers overwritten sectors from a modern drive, whatever a film has suggested.
Continued use destroys evidence. Every hour a machine runs after the relevant event reduces what survives. This is the reason the first-hour advice matters more than the choice of examiner.
Encryption without keys is final. We will not pretend otherwise, and we will tell you at intake rather than after an acquisition invoice.
Anti-forensics, and why it usually backfires
Subjects who try to cover their tracks generally make their position worse, because the covering is itself evidence and it is easier to detect than the original activity.
Wiping utilities leave installation and execution records even when they remove content. Mass deletion in a short window before a resignation is a visible pattern. Timestamps altered to mislead are inconsistent with other records that were not altered. A factory reset is itself a documented event with a time. Cloud synchronisation frequently preserves a copy elsewhere of exactly what was deleted locally.
In practice, “somebody deliberately destroyed material two days before they left” is often a stronger finding for a client than the material itself would have been.
What these examinations are bought for
Departing employees and trade secret cases, where the question is what was copied, connected, uploaded or emailed in the final weeks. Internal fraud and misconduct. Employment and harassment disputes. Family law matters. Insurance and civil litigation. Incident response, where the question is what an intruder actually did on the machine. And preservation in support of a legal hold, before anybody knows precisely what will be needed.
Where the evidence lives elsewhere, it moves to mobile forensics, cloud account extraction or remote collection. Where there are many devices and a budget, field triage establishes which of them are worth examining before the meter runs.
How it is priced
Acquisition is quoted per device by type and capacity, on site or in lab. Analysis is quoted hourly against an agreed scope, with an initial block that establishes whether the question can be answered and roughly what it will take. Expert declaration and testimony are quoted separately.
Included: write-blocked acquisition, hash verification, chain of custody documentation, secure storage of the image for the agreed period, and a written report. Quoted separately: extended analysis, additional devices, expedited turnaround, and testimony.
Frequently asked questions
Can you tell if someone copied files to a USB stick?
Very often, yes — even when the stick is long gone. Connection history, shortcut and jump list artefacts, and file access records frequently establish that a specific device was attached at a specific time and that particular files were opened from it.
Can you recover deleted files from an SSD?
Sometimes, and much less reliably than from a traditional hard drive. SSDs clear deleted blocks automatically as normal maintenance, so content is often genuinely gone. Artefacts showing what was deleted and when usually survive, and are frequently the more useful finding anyway.
The laptop is encrypted and we do not have the password. Now what?
If it is powered off and there is no recovery key, no credential and no management escrow, the honest answer is usually that the content is unreachable. If it is still running and unlocked, that is a completely different situation — which is why calling before powering anything down matters so much.
They wiped the drive. Is it over?
Frequently not, and the wiping is itself a finding. Installation and execution of a wiping tool, the timing relative to a resignation or a legal hold, and inconsistencies with other records that were not wiped all survive. “They destroyed it deliberately, two days before leaving” is often worth more than the files would have been.
How long does an examination take?
Acquisition is usually hours. Analysis depends entirely on the question — a focused question about a defined period is days; a broad examination of several devices is longer. We scope an initial block first so you learn early whether the answer is reachable.
Can we keep using the computer in the meantime?
No. Every hour of use overwrites data and adds activity that has to be separated from the subject’s later. If the machine matters, take it out of service now — that decision protects more evidence than any tool we own.
Who this is for
- Law firms
- Corporate counsel
- Departing-employee matters
- IP theft investigations
- Insurers
- eDiscovery support
Scope your requirement
Do not power the machine on, log in, or run antivirus before we speak. Each of those actions changes evidence. Call 602-725-2818 if the device is currently in someone else’s possession.