Digital Forensics
Remote Forensic Extraction
Evidence acquired from laptops and mobile devices anywhere in the world over secure encrypted protocols — no hardware shipped, no shipping delay.
The device never leaves the custodian
Shipping a device to a lab costs days, risks the chain of custody in transit, and takes the machine away from someone who may need it. For a witness in another state or an employee in another country, it is often simply not practical.
Remote acquisition begins the day authorization is granted. Evidence is acquired over secure encrypted protocols with the same documentation and cross-validation as an in-lab examination, and the custodian keeps the device throughout.
What we deliver
Global Reach
Acquisition from laptops and mobile devices anywhere in the world, without hardware movement.
No Shipping Delay
Work begins the day authorization is granted rather than the day a courier arrives.
Secure Protocols
Encrypted transport with documented integrity verification on everything acquired.
Same Standard
Identical chain of custody documentation and second-tool validation as an in-lab examination.
When the device cannot come to the lab
Traditional forensics assumes possession: the machine arrives, it is imaged under write protection, the original is sealed. That assumption breaks constantly now. The custodian works from another state. The machine is a production server that cannot be shut down. The employee is still employed and the investigation is discreet. The matter is time-critical and shipping costs three days that the evidence may not survive. Or there are forty custodians and one examiner.
Remote forensic collection solves that: a defensible acquisition performed over the network from a device wherever it is, producing a verified image or targeted collection with the same chain of custody as an in-lab acquisition — provided it is done properly, which is where the differences matter.
How it works, and how it differs from an in-lab image
An agent is deployed to the target machine, either by the organisation’s management tooling or with the custodian’s assisted cooperation. The collection runs from that agent to a controlled destination, hashed in flight and verified on arrival, with the entire process logged — what was collected, when, by whom, from which machine and under whose authority.
Two honest differences from a lab acquisition. First, a remote collection is a live collection: the machine is running, so the acquisition itself leaves a footprint on the system and the system continues to change during it. That is manageable and it must be documented, and an examiner who does not disclose it is storing up a cross-examination.
Second, coverage may be narrower. A full physical image over a domestic broadband connection may be impractical — a large drive can take a very long time — so remote work often uses targeted collection: the user profile, the mail store, the artefact set that answers the question, the specific date range. That is frequently better practice anyway, because it is proportionate, but it has to be a deliberate scoping decision recorded in the report rather than a limitation quietly glossed over.
Where it is the right instrument
Distributed and remote workforces, where the custodians are in six states and shipping machines is neither fast nor discreet.
Time-critical preservation, where the evidence is degrading now — a departure, a suspected intrusion, an incoming legal hold — and the alternative is waiting for a courier.
Live systems that cannot be taken down: servers, virtual machines and cloud instances, where memory and running state are part of what needs capturing.
Multi-custodian matters, where collecting twenty machines sequentially in a lab is simply not affordable and parallel remote collection is.
Discreet internal investigations, where removing a laptop announces the investigation to the subject and everyone around them.
Where it is not right: a device that is the subject of a criminal matter and belongs in physical custody; a machine already suspected of active compromise, where the network connection is part of the problem; and a situation where a full physical image is genuinely required and the connection cannot support it. We will say so rather than deliver a thin collection and call it complete.
Authority and consent, again first
Remote collection makes it technically easy to reach a machine, which makes getting the authority right more important rather than less.
Company-owned and managed devices are collected under the organisation’s authority, subject to its policies. Personally owned devices used for work require the custodian’s informed consent, and that consent should be documented and should cover what is being collected — a custodian who agrees to “a work collection” and later discovers their personal photographs were captured is a problem for the case as well as for the person. Where a collection is scoped to a work profile or a date range, that is stated to the custodian in writing.
We do not deploy collection agents to devices we are not authorised to touch, and we do not collect covertly from a personal device on an employer’s say-so. Investigative work in Arizona is licensed under A.R.S. Title 32, Chapter 24; Honeybadger holds Private Investigations Agency licence 1759795.
What you get
A verified image or targeted collection with hash values recorded at source and destination; a complete collection log; a chain of custody from acquisition onward; a written statement of scope including what was deliberately excluded; and secure storage of the evidence for the agreed period. Analysis then proceeds exactly as it would on a lab acquisition.
Where the same matter reaches accounts rather than devices, it runs alongside cloud extraction. Where several devices are in play and only some matter, field triage or a remote triage pass identifies which before full collections are commissioned. Methodology and standards are as set out on the digital forensics page.
Collection kits we ship to you
When an examiner cannot travel and a remote session is not the right fit, we ship a preconfigured collection kit with destination media and step-by-step instructions. The examiner stays on a video call while the custodian follows them.
The kit comes back by tracked shipping with the evidence sealed and logged, and chain of custody is recorded at every handoff. Kits depend on availability; carrier charges, media and the acquisition work itself are included in the written quote.
How it is priced
Quoted per custodian and per device, driven by collection scope, data volume and whether memory capture is included. Multi-custodian matters are quoted as a programme and are materially cheaper per device than sequential lab work. Emergency preservation is quoted as a small standalone engagement, because the right first move is almost always to preserve now and decide later.
Included: authorisation review, scoping, agent deployment, collection, hash verification, collection log and chain of custody, and secure storage for the agreed period. Quoted separately: analysis, memory capture, additional custodians, and testimony.
Frequently asked questions
Is a remote collection as defensible as one done in a lab?
Yes, when it is done properly and honestly described. Same hashing, same chain of custody, same documentation. The difference is that it is a live collection with a disclosed footprint and often a scoped rather than full image — both of which belong in the report rather than being glossed over.
How long does it take?
A targeted collection is often hours. A full image over a domestic connection can take a very long time, which is usually the argument for scoping it deliberately. We will tell you what is realistic on the actual connection before we start rather than after.
Will the custodian know?
That depends on how it is deployed and on what you are lawfully entitled to do. Through management tooling on a company device it can be low-visibility. On a personal device it requires their informed consent, so by definition they will know. We will not collect covertly from a personal device on an employer’s instruction.
Can you collect from a server we cannot take offline?
Yes — live acquisition, including memory where it is relevant, with the effect on the system documented. For servers that is usually the only realistic option, and it is well-established practice provided it is recorded properly.
We have twenty custodians. Can you do them at once?
Yes, and that is where remote collection earns its cost. Parallel collections across a distributed workforce are dramatically faster and cheaper than shipping and imaging twenty machines one at a time.
The machine might be compromised. Should we still collect remotely?
Usually not without thought — the network path is part of the problem, and an active intruder may notice. That situation calls for isolation first and a collection approach designed around it. We will tell you when remote is the wrong instrument rather than defaulting to the convenient one.
Who this is for
- Law firms
- Multi-site corporates
- International matters
- Remote workforces
- Witness devices
- Insurers
Guides on this topic
Scope your requirement
Tell us where the device and custodian are, what authorization exists, and the deadline. Remote acquisition is usually the fastest route to evidence, not the slowest.
Before collection day
What counsel and IT should have ready
Remote collections move fastest when the logistics are settled before the agent is deployed. Most delays come from missing access, unclear custodian lists or a device nobody knew was in scope.
- A custodian list. Names are kept in the engagement file, not in email subject lines, along with each person’s location, time zone and a contact for scheduling.
- A device inventory. For each custodian, the laptops, phones and other devices in scope, who owns them, the operating system and whether they are enrolled in company management tooling.
- Written authorization. The basis for collection from each device: company policy and ownership for managed devices, or documented informed consent for personal ones.
- Scope and date range. The questions the collection must answer, which drives whether a targeted collection is enough.
- An IT contact. Someone who can push the agent through management tooling, confirm network paths and approve temporary exceptions.
- Preservation steps already taken. Suspended auto-deletion, legal hold notices issued and any devices already set aside.
If preservation has not started, our overview of forensic data preservation and legal holds explains what to do first. Under the Federal Rules of Civil Procedure, Rule 37(e) addresses the loss of electronically stored information that should have been preserved, so the timing of preservation matters. This is general information, not legal advice.
Avoidable damage
Mistakes that happen before the examiner is called
Well-meaning people often try to help by collecting evidence themselves. These are the steps that most often reduce what a later forensic collection can show.
Reimaging a returned laptop
IT restores a departing employee’s machine for the next hire. Artifacts showing file access, USB use and cloud uploads are overwritten.
Self-collection by forwarding
A custodian forwards relevant emails to counsel. Forwarding changes metadata and leaves out messages the custodian did not think were relevant.
Screenshots as the only record
Screenshots can help, but without the underlying data they are easy to challenge and hard to authenticate.
Shutting down a live system
Powering off a server or suspected machine discards memory and running state that may have been part of the evidence.
Announcing the investigation
Telling the subject, or disabling their account in a visible way before collection, invites deletion from devices the organization does not control.
Special situations
Phones, borders and review platforms
Some remote matters need additional planning beyond a standard laptop collection.
Mobile devices
Remote phone collection is usually custodian-assisted, with the examiner guiding the process in real time. What can be acquired depends on the device model, operating system and security settings, and that scope is recorded in the report.
Custodians outside the United States
Privacy and data-transfer laws in the custodian’s country may limit what can be collected or where it can be stored. Requirements vary; confirm with counsel familiar with that jurisdiction before collection.
Accounts alongside devices
Much of a custodian’s data may live in email, chat and file-sharing accounts rather than on the device. Our cloud account extraction service collects that data under the same documentation.
Loading into review
Collections can be processed and delivered in formats suited to attorney review, including load files for review platforms, through our eDiscovery litigation support.
To scope a remote collection, request a confidential consultation with the custodian locations, device types and your deadline.