Document metadata · author · created modified printed · revision count · Office · PDF
Document metadata. A document carries, inside itself, a quiet record of who made it, when, and how often it changed.
Every Office document and most PDFs carry metadata inside the file: the author recorded by the application, the dates the document was created, last modified and, often, last printed, the number of revisions, the template it was based on, and sometimes the names of people who edited it. For most documents this is incidental; in a dispute it can speak to when a document was really prepared or altered, which matters where a document's date is in question, a contract said to have been signed on one date but whose metadata shows it was created later, a letter produced in disclosure whose properties tell a different story. The report sets out the metadata of the documents in scope. Its one important caution, which we always give, is that metadata is written by software and can be edited, so it is reported as found and read alongside other evidence, the file-system dates, the journal, the shadow copies, rather than taken as conclusive on its own.
Rather talk it through? An engineer answers the bench line
0800 6890668
What a document records about itself, and how far to trust it.
When an application saves a document, it writes metadata into the file: Microsoft Office records the author, the company, the created and last-modified dates, usually the last-printed date, the number of revisions and the editing time, and the template; PDFs record a producer, creation and modification dates, and sometimes an author. This is separate from the file-system dates the operating system keeps, and it travels inside the file, so it survives the document being copied or emailed.
The evidential use is in questions of when and by whom. A document whose metadata shows it was created after the date it purports to bear, or printed on a date inconsistent with the account of events, or authored by someone other than its supposed author, raises questions the report can set out factually. The revision count and editing time can speak to whether a document was quickly fabricated or genuinely worked on over time.
The caution is essential and we always give it: metadata is written by software and can be edited, by changing the system clock before saving, by editing the document properties directly, or with tools made for the purpose. So the report presents metadata as found, notes where it is internally inconsistent, and reads it alongside the harder-to-alter evidence, the file-system dates, the change journal, the shadow copies, rather than resting a conclusion on metadata alone. Taken together, those sources are far stronger than any one.
What it records, and what it means.
Describe your situation →| What is recorded | Where it comes from | What it shows, and does not |
|---|---|---|
| A document's author and dates | The metadata inside the file | What the document records; metadata can be edited |
| When it was created or last modified | The internal created and modified dates | The recorded dates; read against file-system and journal times |
| Whether it was printed, and when | The last-printed metadata | That printing was recorded; not by whom |
| Whether a date is internally consistent | Metadata cross-checked with other sources | Inconsistencies, which are flagged; not a definitive true date alone |
From the exhibit arriving to the report.
Work we have closed →The first conversation, and the authority check Free
Tell us the situation, who owns the device, and what you need to know. We tell you whether it is a job we can take on, what authority we will need, and whether the standard report answers your questions or an expert report is called for. That conversation is free, and some enquiries end there, because we will not take work we cannot lawfully or honestly do.
Imaging behind a write blocker, and the hashes
When the exhibit arrives, your authority is checked, the device is logged and photographed, and the drive is connected through a hardware write blocker and imaged bit for bit. MD5 and SHA-256 hashes of the source and the image are computed and verified, so the copy is provably identical. Nothing is examined on the original; every later step is done on the verified image.
The examination, on the image
The image is examined for the artefacts your questions turn on: USB device history, files opened from removable media, cloud and webmail activity, deleted files and the Recycle Bin, the USN journal, program execution, email, document metadata, shadow copies, and a timeline. Findings that matter are confirmed in a second tool. The work is scoped to what you asked; material outside the scope is not reproduced.
The report
The standard forensic report sets out the exhibit and its condition, the integrity record, the tools and method, and the findings by category, with a timeline, the limitations, and factual conclusions, as a self-contained report with its chain-of-custody and case-log reports. It is written in plain terms, keeps fact separate from any comment, and is suitable for internal decisions, HR processes, negotiations and solicitors. Where you need opinion evidence for court, an expert report is quoted.
From the bench
- Preserve the original files; metadata travels inside the file, but file-system dates and shadow copies that corroborate it live on the device.
- Tell us which documents and dates are in question; metadata is most useful focused on the documents that matter.
- Do not treat metadata as conclusive alone; it can be edited, and its strength is in corroboration.
Metadata travels inside the file, surviving copying and emailing, but it can be edited, so it is read alongside the harder-to-alter file-system and journal evidence.
What helps, and what harms.
Do this much first
- Stop using the device and keep it powered off
- Preserve it as it is; record who has held it
- Gather your proof of ownership or authority
- Tell us the questions you need answered
What sets us back
- Letting IT or anyone open it to have a look
- Reinstalling, wiping or running recovery software
- Carrying on using the device
- Assuming artefacts prove who was at the keyboard
Questions answered before you instruct.
Can you tell when a document was really created?
Often, to a degree. A document's internal metadata records its created, modified and last-printed dates, and the report sets these out and compares them with the file-system dates, the change journal and any shadow copies. Where these agree, the picture is strong; where the metadata alone disagrees, we note that metadata can be edited and read it with the other evidence.
Can document metadata be faked?
Yes. Metadata is written by software and can be altered, by changing the system clock before saving, by editing the document properties, or with purpose-made tools. That is why we report it as found, flag inconsistencies, and corroborate it with harder-to-alter evidence rather than rest a conclusion on metadata alone.
Can you show who wrote a document?
The metadata records an author field, which reflects the name configured in the application that saved it, not necessarily the true author, and it can be edited. So it is evidence of the recorded author, read alongside other sources, not proof of authorship on its own.
Is this useful for a disputed contract or letter?
It can be, where a document's date or authorship is in question. A document whose properties are inconsistent with the date it bears, or with the account of events, raises questions the report can set out factually, for you and your solicitor to weigh with the rest of the evidence.
What does it cost?
Document metadata examination is part of the standard forensic report, £800 + VAT for a one-disk system. The first conversation is free.
The record is on the device; preserve it first.
The first conversation is free. Tell us the situation and who owns the device, and we will tell you what the evidence can show, what it cannot, and whether we can take it on. Until then, stop using the device and preserve it as it is.