Taking instructions now — the first conversation is freeExhibits posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
FDRForensic Data Recovery 0800 6890668 Price my job
FDR / What the evidence can show / A timeline of user activity

Timeline · sequence of events · UTC · timestamps · corroboration · MACB times

A timeline of user activity. Each artefact is a moment; a timeline puts the moments in order, so a sequence can be seen rather than a scatter of facts.

Individually, the artefacts on a computer are moments: a device connected at one time, a file opened at another, a deletion at a third. A timeline is what turns those scattered moments into a sequence, and the sequence is often where the meaning lies. By assembling the USB connections, the files opened, the programs run, the deletions, the logons and the web activity into one list, ordered by time and presented in UTC with the local offset noted, the examination lets you see the order in which things happened: a USB device connected, folders opened from it, a cloud client installed, files deleted, the Recycle Bin emptied, a logoff. The standard report provides a timeline extract for the period that matters. It is careful about timestamps, which are generally reliable but can be affected by time zones, clock drift, copying and deliberate tampering, so times are tested against several sources and against the examination workstation, and a single time is never asked to carry more than it can.

Owner-only, authority requiredFree first conversationStandard report £800 + VATWe say what it cannot prove

Rather talk it through? An engineer answers the bench line
0800 6890668

Before anything else: stop using the device, and do not let anyone have a look at it. Every time a computer is switched on and used, the very artefacts an examination relies on, the timeline, the recently-opened lists, the deleted-file space, are overwritten a little more. Do not reinstall, do not run recovery software, do not let IT open it to check, and keep it powered off. Preserve it as it is, record who has held it, and send it with the authority documents we ask for. If proceedings are contemplated, the duty to preserve evidence has already begun.

How a timeline is built, and how far it can be trusted.

Every artefact carries one or more timestamps: a file has created, modified, accessed and record-changed times (together, MACB); a USB connection has a first and last time; a prefetch record has a last-run time; a log entry has its own time. A timeline gathers all of these into one list, sorted by time, so that events from different artefacts can be read in the order they happened rather than category by category.

The value is in the sequence. A scatter of facts, a device, some files, a deletion, becomes a narrative when ordered: the device was connected, then these folders were opened from it, then a cloud client was installed, then these files were deleted, then the Recycle Bin was emptied, then the user logged off. The report presents the timeline for the relevant period, in UTC with the local offset noted, because mixing time zones is a common way to get a sequence wrong.

Timestamps must be handled with care, and we handle them with care. They are generally reliable, but they can be shifted by a time-zone setting, by clock drift, by copying a file (which changes some times but not others), and by deliberate tampering. So we test times against several artefacts, check the system clock against the examination workstation, and note any anomalies, rather than build a conclusion on a single timestamp that might be wrong.

What it records, and what it means.

Describe your situation →
What is recorded Where it comes from What it shows, and does not
The order of events in a periodAll artefact timestamps, merged and sortedThe order, where the timestamps are sound; not the motive
When a sequence began and endedFirst and last events in the periodThe sequence, not who performed it
Whether times are internally consistentCross-checking artefacts against each otherThat no time was tampered with; anomalies are flagged
The local time of eventsUTC converted with the system offsetThe offset is as configured; a wrong setting is noted

From the exhibit arriving to the report.

Work we have closed →
01

The first conversation, and the authority check Free

Tell us the situation, who owns the device, and what you need to know. We tell you whether it is a job we can take on, what authority we will need, and whether the standard report answers your questions or an expert report is called for. That conversation is free, and some enquiries end there, because we will not take work we cannot lawfully or honestly do.

FreeOwner-only; authority established firstThe honest answer about what is possible
02

Imaging behind a write blocker, and the hashes

When the exhibit arrives, your authority is checked, the device is logged and photographed, and the drive is connected through a hardware write blocker and imaged bit for bit. MD5 and SHA-256 hashes of the source and the image are computed and verified, so the copy is provably identical. Nothing is examined on the original; every later step is done on the verified image.

Bit-for-bit, behind a write blockerMD5 and SHA-256, verifiedThe original never altered
03

The examination, on the image

The image is examined for the artefacts your questions turn on: USB device history, files opened from removable media, cloud and webmail activity, deleted files and the Recycle Bin, the USN journal, program execution, email, document metadata, shadow copies, and a timeline. Findings that matter are confirmed in a second tool. The work is scoped to what you asked; material outside the scope is not reproduced.

Scoped to your questionsConfirmed in a second toolPrivate material filtered out
04

The report

The standard forensic report sets out the exhibit and its condition, the integrity record, the tools and method, and the findings by category, with a timeline, the limitations, and factual conclusions, as a self-contained report with its chain-of-custody and case-log reports. It is written in plain terms, keeps fact separate from any comment, and is suitable for internal decisions, HR processes, negotiations and solicitors. Where you need opinion evidence for court, an expert report is quoted.

Factual, tool-generated, self-containedChain-of-custody and case-log reports5–10 working days

From the bench

  • Tell us the dates that matter; a timeline is most useful focused on the relevant period rather than the whole history.
  • Preserve the machine; a timeline is only as complete as the artefacts that survive on the device.
  • Treat a single timestamp with caution; the strength is in corroborated sequence, not one time.

Mixing time zones is a common way to get a sequence wrong, which is why a forensic timeline is presented in UTC with the local offset noted.

What helps, and what harms.

Do this much first

  • Stop using the device and keep it powered off
  • Preserve it as it is; record who has held it
  • Gather your proof of ownership or authority
  • Tell us the questions you need answered

What sets us back

  • Letting IT or anyone open it to have a look
  • Reinstalling, wiping or running recovery software
  • Carrying on using the device
  • Assuming artefacts prove who was at the keyboard
We examine devices only for the people and organisations with lawful authority over them. Before any work begins we ask for proof that the device is yours, or documented authority to have it examined: proof of ownership, a director's or HR letter for a company device with the lawful basis, a solicitor's instruction, a court order, or an executor's grant. It is a condition of the work, not a formality, and it is what keeps the examination on the right side of the Computer Misuse Act 1990. We will not access another adult's device or accounts without their consent or a court order, we will not install monitoring software or bypass anyone's security, and we do not undertake covert surveillance. A device with no proof of authority is returned unexamined.

Questions answered before you instruct.

What is a forensic timeline?

It is the separate artefacts on a computer, USB connections, files opened, programs run, deletions, logons, web activity, assembled into one list ordered by time. It lets the sequence of events be seen, which is often where the meaning lies, rather than reading each category of evidence in isolation.

How reliable are the times?

File and system timestamps are generally reliable, but they can be affected by time-zone settings, clock drift, copying and deliberate tampering. We test times against several artefacts and against the examination workstation, present them in UTC, and flag anomalies, so a conclusion never rests on a single time that might be wrong.

Can a timeline show who did something?

It shows the order of events, under which user account, and when. Like every artefact, it shows the account and the time, not the person at the keyboard. Its strength is in making a sequence clear, which, with corroboration, is often what a matter turns on.

Can timestamps be faked?

They can be altered deliberately, which is why we do not rely on a single timestamp. Tampering often leaves inconsistencies between artefacts that a careful examination detects, and we flag anomalies rather than present a tampered time as sound.

What does it cost?

A timeline extract for the relevant period is part of the standard forensic report, £800 + VAT for a one-disk system. The first conversation is free.

The record is on the device; preserve it first.

The first conversation is free. Tell us the situation and who owns the device, and we will tell you what the evidence can show, what it cannot, and whether we can take it on. Until then, stop using the device and preserve it as it is.

0800 6890668