Remote Forensic Extraction
Evidence acquired from laptops and mobile devices anywhere in the world over secure encrypted protocols — no hardware shipped, no shipping delay.
The device never leaves the custodian
Shipping a device to a lab costs days, risks the chain of custody in transit, and takes the machine away from someone who may need it. For a witness in another state or an employee in another country, it is often simply not practical.
Remote acquisition begins the day authorization is granted. Evidence is acquired over secure encrypted protocols with the same documentation and cross-validation as an in-lab examination, and the custodian keeps the device throughout.
What we deliver
Global Reach
Acquisition from laptops and mobile devices anywhere in the world, without hardware movement.
No Shipping Delay
Work begins the day authorization is granted rather than the day a courier arrives.
Secure Protocols
Encrypted transport with documented integrity verification on everything acquired.
Same Standard
Identical chain of custody documentation and second-tool validation as an in-lab examination.
When the device cannot come to the lab
Traditional forensics assumes possession: the machine arrives, it is imaged under write protection, the original is sealed. That assumption breaks constantly now. The custodian works from another state. The machine is a production server that cannot be shut down. The employee is still employed and the investigation is discreet. The matter is time-critical and shipping costs three days that the evidence may not survive. Or there are forty custodians and one examiner.
Remote forensic collection solves that: a defensible acquisition performed over the network from a device wherever it is, producing a verified image or targeted collection with the same chain of custody as an in-lab acquisition — provided it is done properly, which is where the differences matter.
How it works, and how it differs from an in-lab image
An agent is deployed to the target machine, either by the organisation’s management tooling or with the custodian’s assisted cooperation. The collection runs from that agent to a controlled destination, hashed in flight and verified on arrival, with the entire process logged — what was collected, when, by whom, from which machine and under whose authority.
Two honest differences from a lab acquisition. First, a remote collection is a live collection: the machine is running, so the acquisition itself leaves a footprint on the system and the system continues to change during it. That is manageable and it must be documented, and an examiner who does not disclose it is storing up a cross-examination.
Second, coverage may be narrower. A full physical image over a domestic broadband connection may be impractical — a large drive can take a very long time — so remote work often uses targeted collection: the user profile, the mail store, the artefact set that answers the question, the specific date range. That is frequently better practice anyway, because it is proportionate, but it has to be a deliberate scoping decision recorded in the report rather than a limitation quietly glossed over.
Where it is the right instrument
Distributed and remote workforces, where the custodians are in six states and shipping machines is neither fast nor discreet.
Time-critical preservation, where the evidence is degrading now — a departure, a suspected intrusion, an incoming legal hold — and the alternative is waiting for a courier.
Live systems that cannot be taken down: servers, virtual machines and cloud instances, where memory and running state are part of what needs capturing.
Multi-custodian matters, where collecting twenty machines sequentially in a lab is simply not affordable and parallel remote collection is.
Discreet internal investigations, where removing a laptop announces the investigation to the subject and everyone around them.
Where it is not right: a device that is the subject of a criminal matter and belongs in physical custody; a machine already suspected of active compromise, where the network connection is part of the problem; and a situation where a full physical image is genuinely required and the connection cannot support it. We will say so rather than deliver a thin collection and call it complete.
Authority and consent, again first
Remote collection makes it technically easy to reach a machine, which makes getting the authority right more important rather than less.
Company-owned and managed devices are collected under the organisation’s authority, subject to its policies. Personally owned devices used for work require the custodian’s informed consent, and that consent should be documented and should cover what is being collected — a custodian who agrees to “a work collection” and later discovers their personal photographs were captured is a problem for the case as well as for the person. Where a collection is scoped to a work profile or a date range, that is stated to the custodian in writing.
We do not deploy collection agents to devices we are not authorised to touch, and we do not collect covertly from a personal device on an employer’s say-so. Investigative work in Arizona is licensed under A.R.S. Title 32, Chapter 24; Honeybadger holds Private Investigations Agency licence 1759795.
What you get
A verified image or targeted collection with hash values recorded at source and destination; a complete collection log; a chain of custody from acquisition onward; a written statement of scope including what was deliberately excluded; and secure storage of the evidence for the agreed period. Analysis then proceeds exactly as it would on a lab acquisition.
Where the same matter reaches accounts rather than devices, it runs alongside cloud extraction. Where several devices are in play and only some matter, field triage or a remote triage pass identifies which before full collections are commissioned. Methodology and standards are as set out on the digital forensics page.
How it is priced
Quoted per custodian and per device, driven by collection scope, data volume and whether memory capture is included. Multi-custodian matters are quoted as a programme and are materially cheaper per device than sequential lab work. Emergency preservation is quoted as a small standalone engagement, because the right first move is almost always to preserve now and decide later.
Included: authorisation review, scoping, agent deployment, collection, hash verification, collection log and chain of custody, and secure storage for the agreed period. Quoted separately: analysis, memory capture, additional custodians, and testimony.
Frequently asked questions
Is a remote collection as defensible as one done in a lab?
Yes, when it is done properly and honestly described. Same hashing, same chain of custody, same documentation. The difference is that it is a live collection with a disclosed footprint and often a scoped rather than full image — both of which belong in the report rather than being glossed over.
How long does it take?
A targeted collection is often hours. A full image over a domestic connection can take a very long time, which is usually the argument for scoping it deliberately. We will tell you what is realistic on the actual connection before we start rather than after.
Will the custodian know?
That depends on how it is deployed and on what you are lawfully entitled to do. Through management tooling on a company device it can be low-visibility. On a personal device it requires their informed consent, so by definition they will know. We will not collect covertly from a personal device on an employer’s instruction.
Can you collect from a server we cannot take offline?
Yes — live acquisition, including memory where it is relevant, with the effect on the system documented. For servers that is usually the only realistic option, and it is well-established practice provided it is recorded properly.
We have twenty custodians. Can you do them at once?
Yes, and that is where remote collection earns its cost. Parallel collections across a distributed workforce are dramatically faster and cheaper than shipping and imaging twenty machines one at a time.
The machine might be compromised. Should we still collect remotely?
Usually not without thought — the network path is part of the problem, and an active intruder may notice. That situation calls for isolation first and a collection approach designed around it. We will tell you when remote is the wrong instrument rather than defaulting to the convenient one.
Who this is for
- Law firms
- Multi-site corporates
- International matters
- Remote workforces
- Witness devices
- Insurers
Scope your requirement
Tell us where the device and custodian are, what authorization exists, and the deadline. Remote acquisition is usually the fastest route to evidence, not the slowest.