Digital Forensics
Computer & Hard Drive Forensics
Volatile memory capture, encrypted volume access and deleted file carving from workstations, servers and storage media.
Computer and hard drive forensics is the sound acquisition and analysis of laptops, desktops, servers and storage media to show what a user did and when: files copied to USB, documents opened, uploads, deletions and wiping. The original is never altered. A write-blocked, hash-verified image is examined instead, and findings are reported in a form courts can rely on.
What the machine did, and when
Computer forensics answers questions a user cannot: what was copied to that USB device, what was accessed the night before a resignation, what was running in memory when the incident occurred, what was deliberately deleted and when.
Acquisition is performed to a forensically sound standard, from the drive image through to volatile memory and hibernation files. Encrypted volumes including BitLocker and FileVault are addressed where authorization exists.
What we deliver
Volatile Memory & Hibernation
RAM and hibernation file capture preserving evidence that disappears at shutdown.
Encrypted Volumes
BitLocker and FileVault volumes addressed where lawful authority has been established.
Deleted File Carving
Images, video and documents recovered from unallocated space and file system remnants.
OCR & Keyword Triage
Transcription, OCR and keyword indexing across recovered material to find what matters.
How a drive is actually acquired
The examination never touches the original. A hardware or software write blocker prevents any change to the source, a complete bit-for-bit image is taken, and cryptographic hashes are calculated at acquisition and verified afterwards so that any alteration would be detectable by anyone who checks. The original is sealed and stored; every subsequent step happens on the verified copy.
Where the machine cannot be shut down — a production server, a system holding volatile evidence, a drive whose encryption key exists only in memory — a live acquisition is performed instead, with the actions taken and their effect on the system documented contemporaneously. Live acquisition is not a shortcut; it is a considered decision with its own record, and an examiner who cannot explain why they chose it has a problem.
Encryption is where cases are won and lost before analysis begins. A powered-off machine with full-disk encryption and no key, no recovery key and no credential is, for practical purposes, a brick. A machine that is running and unlocked is an entirely different proposition. That is the single strongest argument for calling before anybody powers something down.
What a disk actually remembers
Most people picture forensics as recovering deleted files. That is part of it and rarely the important part. The important part is the record a computer keeps of what a person did, which is far more extensive than users realise.
File system records retain creation, modification and access times, and the change journal often shows activity for files that no longer exist.
Registry and system artefacts record which USB devices were connected and when, which folders were browsed, which documents were opened, which applications were run and how often. For a departing-employee case, USB connection history alone frequently answers the question.
Shortcut and jump list artefacts survive the files they point to, showing that a document existed on a removable drive even when the drive is long gone.
Execution artefacts show what ran, when and from where — including portable applications launched from a USB stick and never installed.
Event logs record logons, sessions, service activity and errors, and often the exact clock.
Browser and webmail traces show searches, uploads to personal cloud storage and webmail attachments — the modern route data actually leaves by.
Cloud client artefacts from synchronisation applications record which files synchronised to a personal account and when.
Shadow copies, hibernation and page files preserve older states of the system, and frequently contain material the user believes was deleted.
Unallocated space holds recoverable fragments of deleted content — sometimes.
The limits, stated honestly
Solid-state drives change what is recoverable. Modern SSDs actively clear blocks marked as deleted, as a normal part of maintaining performance, and this happens without user involvement. On an SSD that has been powered on since a deletion, deleted file content is frequently unrecoverable — not because the examiner lacks skill, but because the drive erased it. Anyone promising routine deleted-file recovery from an SSD is overstating it. Metadata and artefacts about the deletion often still survive, and are frequently sufficient.
Overwritten is gone. Data that has been overwritten by new content is not recoverable, by anyone, with any tool. There is no laboratory technique that recovers overwritten sectors from a modern drive, whatever a film has suggested.
Continued use destroys evidence. Every hour a machine runs after the relevant event reduces what survives. This is the reason the first-hour advice matters more than the choice of examiner.
Encryption without keys is final. We will not pretend otherwise, and we will tell you at intake rather than after an acquisition invoice.
Anti-forensics, and why it usually backfires
Subjects who try to cover their tracks generally make their position worse, because the covering is itself evidence and it is easier to detect than the original activity.
Wiping utilities leave installation and execution records even when they remove content. Mass deletion in a short window before a resignation is a visible pattern. Timestamps altered to mislead are inconsistent with other records that were not altered. A factory reset is itself a documented event with a time. Cloud synchronisation frequently preserves a copy elsewhere of exactly what was deleted locally.
In practice, “somebody deliberately destroyed material two days before they left” is often a stronger finding for a client than the material itself would have been.
What these examinations are bought for
Departing employees and trade secret cases, where the question is what was copied, connected, uploaded or emailed in the final weeks. Internal fraud and misconduct. Employment and harassment disputes. Family law matters. Insurance and civil litigation. Incident response, where the question is what an intruder actually did on the machine. And preservation in support of a legal hold, before anybody knows precisely what will be needed.
Where the evidence lives elsewhere, it moves to mobile forensics, cloud account extraction or remote collection. Where there are many devices and a budget, field triage establishes which of them are worth examining before the meter runs.
Hard drives vs. SSDs: what can be recovered
The type of storage changes what a forensic examination can realistically deliver. It is one of the first things we ask about, because it sets expectations before any money is spent.
| Question | Traditional hard drive (HDD) | Solid-state drive (SSD) |
|---|---|---|
| Deleted file content | Often recoverable until the space is overwritten | Often erased automatically soon after deletion (TRIM and garbage collection) |
| Evidence that a file existed and was deleted | Usually survives in file system and system records | Usually survives in file system and system records |
| USB, upload and file-access history | Usually survives | Usually survives |
| Effect of continued use | Gradual overwriting of deleted areas | Faster loss of deleted content |
| Full-disk encryption without a key | Content unreachable | Content unreachable |
| Evidence of wiping tools | Installation and execution traces usually survive | Installation and execution traces usually survive |
This is why the examination is about the record a computer keeps of activity, not only about undeleting files. Our guides on SSD forensics and data recovery and hard drive forensic recovery go deeper on each.
The first hour: protecting computer evidence
What happens before an examiner arrives often decides the case. NIST SP 800-86, the federal guide to integrating forensics into incident response, makes the same point: preserve first, examine later. If a computer may hold evidence, do this:
- Leave a running machine running. If it is on and possibly encrypted, shutting it down can lock the data behind a key you do not have. Call before anyone powers it off.
- Leave a powered-off machine off. Turning it on changes timestamps and logs and lets automatic cleanup run.
- Stop anyone from looking around. IT staff browsing folders, copying files or running antivirus scans all overwrite evidence and create questions about who did what.
- Collect the encryption recovery keys. For company devices, BitLocker or FileVault recovery keys are often escrowed in Microsoft Entra ID, Active Directory or device management. Retrieve them early.
- Preserve the surroundings. Cloud sync accounts, email, backups and USB devices found nearby are often as important as the drive itself.
- Write down who had access. Names, dates and what each person did with the device. This becomes the start of your chain of custody.
- Put a legal hold in place. If litigation is possible, suspend routine deletion and device reissue for the people involved.
For matters headed to litigation, see e-discovery and litigation support and our guide to hiring a digital forensics expert.
Macs and very large drives
We image Windows and Linux computers and Macs. Macs need more planning. On Macs with Apple silicon or the T2 security chip, the internal SSD is encrypted by the hardware (see Apple Platform Security), so a useful acquisition usually needs the user’s password or FileVault recovery key and is often done with the computer running. We record the method chosen for that Mac’s hardware and encryption so it can be explained in a report.
Drives larger than one terabyte, multi-disk computers, USB drives, memory cards and external disks are imaged too. We confirm capacity, condition and the destination media before work starts, and every image is hash-verified.
How it is priced
Acquisition is quoted per device by type and capacity, on site or in lab. Analysis is quoted hourly against an agreed scope, with an initial block that establishes whether the question can be answered and roughly what it will take. Expert declaration and testimony are quoted separately.
Included: write-blocked acquisition, hash verification, chain of custody documentation, secure storage of the image for the agreed period, and a written report. Quoted separately: extended analysis, additional devices, expedited turnaround, and testimony.
Frequently asked questions
What is a forensic image?
A forensic image is a complete, bit-for-bit copy of a drive, including deleted and unallocated space, made through a write blocker so the original is not changed. It is hashed when it is made and again before analysis, which proves the copy is identical to the source. All examination happens on the image, never the original.
Can you prove who was using the computer?
Forensics can show which user account did something and when, and it often narrows down who was at the keyboard using logons, device connections and timing. Tying an account to a specific person usually needs other evidence as well, such as access records, witness accounts or camera footage. We report what the artifacts support and do not overstate it.
Can you tell if someone copied files to a USB stick?
Very often, yes — even when the stick is long gone. Connection history, shortcut and jump list artefacts, and file access records frequently establish that a specific device was attached at a specific time and that particular files were opened from it.
Can you recover deleted files from an SSD?
Sometimes, and much less reliably than from a traditional hard drive. SSDs clear deleted blocks automatically as normal maintenance, so content is often genuinely gone. Artefacts showing what was deleted and when usually survive, and are frequently the more useful finding anyway.
The laptop is encrypted and we do not have the password. Now what?
If it is powered off and there is no recovery key, no credential and no management escrow, the honest answer is usually that the content is unreachable. If it is still running and unlocked, that is a completely different situation — which is why calling before powering anything down matters so much.
They wiped the drive. Is it over?
Frequently not, and the wiping is itself a finding. Installation and execution of a wiping tool, the timing relative to a resignation or a legal hold, and inconsistencies with other records that were not wiped all survive. “They destroyed it deliberately, two days before leaving” is often worth more than the files would have been.
How long does an examination take?
Acquisition is usually hours. Analysis depends entirely on the question — a focused question about a defined period is days; a broad examination of several devices is longer. We scope an initial block first so you learn early whether the answer is reachable.
Can we keep using the computer in the meantime?
No. Every hour of use overwrites data and adds activity that has to be separated from the subject’s later. If the machine matters, take it out of service now — that decision protects more evidence than any tool we own.
Who this is for
- Law firms
- Corporate counsel
- Departing-employee matters
- IP theft investigations
- Insurers
- eDiscovery support
Guides on this topic
Scope your requirement
Do not power the machine on, log in, or run antivirus before we speak. Each of those actions changes evidence. Use the urgent intake form if the device is currently in someone else’s possession.