Digital Forensics
Digital Forensics Service List
Every digital forensics service we offer, grouped by what you need: collecting evidence from phones, computers, cloud accounts and online sources, analyzing it, and presenting it in court. Each one can be requested online on its own or combined into one engagement.
Everything we do in digital forensics
Every service below can be requested online on its own or combined into one engagement. Pricing depends on the devices, data volume and deadline; we quote in writing before any work starts.
Phones and tablets (3)
- Standard phone extraction: An unlocked phone with the passcode supplied: logical or backup extraction with evidence intake, chain of custody and integrity verification.
- Advanced phone extraction: Full file-system acquisition and tool parsing where the model and operating system support it.
- Locked or damaged phone assessment: An examiner checks what is possible on a locked, broken or water-damaged device before any extraction attempt.
Remote, cloud and online collection (11)
- Remote targeted collection: Collection of agreed folders from a reachable computer without a site visit.
- Remote collection kits: We ship a preconfigured collection kit and handle its return.
- On-site collection: An examiner comes to your location to collect evidence in person.
- Email mailbox collection: Microsoft 365, Google Workspace and Exchange mailboxes, exported and verified.
- Cloud tenant collection: Setup and validation of a defensible export from a Microsoft 365 or Google tenant.
- Cloud files and chat: OneDrive, SharePoint, Google Drive, Dropbox, Slack and Teams.
- Social media preservation: Authorized export of an account for a set date range.
- Website capture: A documented capture of web pages for court.
- Servers and file shares: Targeted collection from servers and shared drives.
- Databases: Structured database extraction in an agreed format.
- AWS and Azure evidence: Authorized snapshots and log exports from cloud accounts.
Computers, drives and media (6)
- Windows and Linux disk imaging: Forensic image of a hard drive or SSD with hash verification.
- Mac acquisition: Logical or physical acquisition of a Mac, documented to suit its hardware and encryption.
- Large and multi-terabyte drives: Imaging of drives larger than one terabyte.
- USB drives, memory cards and external media: Imaging of thumb drives, SD cards and external drives.
- Cameras and memory cards: Photo and video export with a full EXIF metadata inventory.
- CCTV, DVRs, IoT and legacy media: Tapes, security-camera recorders, smart devices and unusual systems.
Reports, testimony and evidence handling (5)
- Chain-of-custody audit: Review or reconstruction of custody records for existing evidence.
- Acquisition declaration: A sworn factual declaration describing how evidence was acquired.
- Expert report: Methods, findings, limitations and exhibits in a written report.
- Opposing expert review: A check of the other side’s methods, data and conclusions.
- Deposition and trial testimony: Expert testimony at deposition, hearing or trial.
Analysis (12)
- Forensic triage: A short review that confirms what evidence exists and recommends the analysis scope.
- Deleted data recovery: Recovery of deleted files, messages and database remnants.
- User activity reconstruction: Registry, event logs, shortcuts and application traces that show what a user did.
- Timelines across devices: Events from several devices, normalized to one timeline.
- Email header and metadata analysis: Routing, timestamps and anomalies in email messages.
- Photo, file and location analysis: Metadata and location artifacts in files and pictures.
- Server and network log analysis: Authentication, traffic and security logs reviewed by a senior examiner.
- Intellectual property theft: Copying, external devices and data leaving with departing employees.
- Employee misconduct and fraud: Review of the communications and artifacts that matter to the allegation.
- Database and application forensics: Audit trails, custom schemas and transaction histories.
- Digital financial and crypto tracing: Tracing transactions and wallets from the source data.
- Spyware and stalkerware assessment: A check of a phone or computer for spyware, remote access and tracking.
How pricing and requests work
We do not list prices because the right scope depends on your devices, data, users and deadline. Every engagement is quoted in writing before any work starts, and nothing is charged before you accept. Request any service online and pick it from the list: your request goes straight to the team that handles it, so there is no phone tag. If something is happening right now, use the urgent request page.
Want the overview first? Read how our digital forensics work runs from preservation to the final report.
Not sure which service you need?
Describe the situation in the online request. We will match it to the right service, or combination of services, and confirm the scope in writing.