USB · removable media · cloud · timeline · deletion · email · metadata · shadow copies · encryption
What the evidence can show. The record on a computer is detailed, survives deletion, and has one consistent limit.
A modern computer keeps a remarkably detailed record of what is done on it, and most of that record survives the files themselves being deleted. Windows remembers every USB device connected, with its serial and dates; it records which files were opened from a removable drive; it logs when software was installed and run; it keeps a journal of deletions; and it builds, almost incidentally, a timeline of user activity. Much of this is what makes a forensic examination worth doing. Each page below takes one category of evidence, explains what it records and where it comes from, and sets out, honestly, what it can show and what it cannot. The consistent limit, stated in every report we write, is that these artefacts show the account that was used and when, not the person who was at the keyboard, and that they record what happened, not why. Understanding that is the difference between evidence a solicitor can rely on and an overreach that falls apart under challenge.
Rather talk it through? An engineer answers the bench line
0800 6890668
How this evidence survives, and why it is worth examining.
The evidence, by category.
Describe your situation → →Who did what, and when
USB device historyEvery USB storage device ever connected, with its make, serial and the first and last dates, from the registry and logs→Files opened from removable mediaJump lists, shortcut files and shellbags showing which files were opened from a removable drive, tied to its serial→Cloud sync and webmail activityPersonal cloud clients installed and their upload volume, webmail and transfer-site visits, from logs and browser history→A timeline of user activityThe artefacts assembled into one sortable sequence, so the order of events can be seen where the data supports it→Program execution and wiping toolsPrefetch and execution records showing what was run and when, including a cleaning or wiping tool and its settings→What was there, and what was removed
Deleted files and the Recycle BinDeleted files recovered with a recoverability measure, and the Recycle Bin records of what was removed and when→Mass deletion and the USN journalThe change journal's timestamped record of deletions, so a mass deletion can be placed to the hour→Email archives: PST, OST and mailbox rulesLocal mail recovered, deleted messages brought back, and forwarding or auto-delete rules with their creation times→Document metadataA document's created, modified and last-printed dates and author field, as held inside the file→Volume Shadow Copies and earlier versionsEarlier versions of key documents, so what a file said at an earlier date can be shown→Encrypted files and drivesDetection of encrypted files and disks, and recovery with the key, password or a memory capture, in the authorised context→The questions that come up first.
Can a forensic examination prove who did something on a computer?
It can prove what was done, under which user account, and when, to the standard the artefacts allow. It cannot, on its own, prove who was physically at the keyboard; that usually needs corroboration from outside the device. We are clear about this distinction in every report, because it is what makes the evidence reliable.
If a file was deleted, is it gone?
Often not. Deleting a file removes the pointer to it, not the data, until the space is reused, so deleted files are frequently recoverable, and the records about the file, when it was opened and from where, survive independently. An SSD's TRIM feature is the main thing that destroys deleted data quickly.
How reliable are the timestamps?
File and system timestamps are generally reliable, but they can be affected by time zones, clock drift, copying and deliberate tampering, so we test them against several sources and against the examination workstation, and build a timeline rather than rely on a single time.
Which tools do you use?
The standard examination is produced with PassMark OSForensics, and findings that matter are confirmed in a second tool such as Autopsy. Each report lists the tools and versions used, so the method is transparent and repeatable.
The record is on the device; preserve it first.
Each page sets out what a category of evidence can show and what it cannot. Tell us the situation and who owns the device, and the first conversation will tell you honestly what is possible.