Taking instructions now — the first conversation is freeExhibits posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
FDRForensic Data Recovery 0800 6890668 Price my job
FDR / What the evidence can show

USB · removable media · cloud · timeline · deletion · email · metadata · shadow copies · encryption

What the evidence can show. The record on a computer is detailed, survives deletion, and has one consistent limit.

A modern computer keeps a remarkably detailed record of what is done on it, and most of that record survives the files themselves being deleted. Windows remembers every USB device connected, with its serial and dates; it records which files were opened from a removable drive; it logs when software was installed and run; it keeps a journal of deletions; and it builds, almost incidentally, a timeline of user activity. Much of this is what makes a forensic examination worth doing. Each page below takes one category of evidence, explains what it records and where it comes from, and sets out, honestly, what it can show and what it cannot. The consistent limit, stated in every report we write, is that these artefacts show the account that was used and when, not the person who was at the keyboard, and that they record what happened, not why. Understanding that is the difference between evidence a solicitor can rely on and an overreach that falls apart under challenge.

Owner-only, authority requiredFree first conversationStandard report £800 + VATThe honest limits, in writing

Rather talk it through? An engineer answers the bench line
0800 6890668

Before anything else: stop using the device, and do not let anyone have a look at it. Every time a computer is switched on and used, the very artefacts an examination relies on, the timeline, the recently-opened lists, the deleted-file space, are overwritten a little more. Do not reinstall, do not run recovery software, do not let IT open it to check, and keep it powered off. Preserve it as it is, record who has held it, and send it with the authority documents we ask for. If proceedings are contemplated, the duty to preserve evidence has already begun.

How this evidence survives, and why it is worth examining.

Deletion is not destructionDeleting a file removes the pointer to it, not the data, until the space is reused, so deleted files are often recoverable. And the records about a file, that it was opened, from which device, when, live in separate artefacts that a deletion does not touch. This is why an examination so often recovers what someone believed was gone.
The device records more than its user realisesWindows keeps USB histories, recently-opened lists, execution records and a change journal as a matter of course, usually without the user's awareness. These artefacts were designed to make the system convenient, and they double as a detailed record of activity.
The artefacts corroborate each otherA single artefact can be ambiguous; several together are far stronger. A USB device in the registry, the files opened from its volume in the jump lists, and a deletion in the journal tell a fuller story than any one alone, and a timeline draws them together.
The limit is always the same, and always statedAcross every category, the artefacts show the account and the time, not the person at the keyboard, and the action, not the intention. We say this in every report, because an examination that respects its limits produces evidence that holds, and one that ignores them produces a claim that does not.

The evidence, by category.

Describe your situation → →

The questions that come up first.

Can a forensic examination prove who did something on a computer?

It can prove what was done, under which user account, and when, to the standard the artefacts allow. It cannot, on its own, prove who was physically at the keyboard; that usually needs corroboration from outside the device. We are clear about this distinction in every report, because it is what makes the evidence reliable.

If a file was deleted, is it gone?

Often not. Deleting a file removes the pointer to it, not the data, until the space is reused, so deleted files are frequently recoverable, and the records about the file, when it was opened and from where, survive independently. An SSD's TRIM feature is the main thing that destroys deleted data quickly.

How reliable are the timestamps?

File and system timestamps are generally reliable, but they can be affected by time zones, clock drift, copying and deliberate tampering, so we test them against several sources and against the examination workstation, and build a timeline rather than rely on a single time.

Which tools do you use?

The standard examination is produced with PassMark OSForensics, and findings that matter are confirmed in a second tool such as Autopsy. Each report lists the tools and versions used, so the method is transparent and repeatable.

The record is on the device; preserve it first.

Each page sets out what a category of evidence can show and what it cannot. Tell us the situation and who owns the device, and the first conversation will tell you honestly what is possible.

0800 6890668