Taking instructions now — the first conversation is freeExhibits posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
FDRForensic Data Recovery 0800 6890668 Price my job
FDR / What the evidence can show / Volume Shadow Copies and earlier versions

Volume Shadow Copy · VSS · earlier versions · snapshots · prior versions · what it said before

Volume Shadow Copies and earlier versions. Windows quietly keeps earlier snapshots of files, so a document can be seen as it was weeks or months ago.

Windows has a feature, the Volume Shadow Copy Service, that periodically takes snapshots of the drive, and those snapshots can contain earlier versions of files as they were at the time each snapshot was taken. For an examination this is quietly powerful, because it means a document can sometimes be recovered not just as it is now, but as it was weeks or months ago, before it was edited or deleted. Where the question is what a document used to say, a budget before a figure was changed, a schedule of assets before an item was removed, a letter before it was revised, shadow copies can answer it, and the earlier and current versions can be compared. The report recovers the earlier versions that exist for the documents in scope and sets out what each snapshot held and when it was taken. The limits are simply that shadow copies are not always present or complete, Windows manages them automatically and they can be absent, sparse or turned off, so they are a valuable source when they exist, not a guaranteed one.

Owner-only, authority requiredFree first conversationStandard report £800 + VATWe say what it cannot prove

Rather talk it through? An engineer answers the bench line
0800 6890668

Before anything else: stop using the device, and do not let anyone have a look at it. Every time a computer is switched on and used, the very artefacts an examination relies on, the timeline, the recently-opened lists, the deleted-file space, are overwritten a little more. Do not reinstall, do not run recovery software, do not let IT open it to check, and keep it powered off. Preserve it as it is, record who has held it, and send it with the authority documents we ask for. If proceedings are contemplated, the duty to preserve evidence has already begun.

How earlier versions are recovered, and when they exist.

The Volume Shadow Copy Service (VSS) takes point-in-time snapshots of a Windows volume, used by features like System Restore and backup. Each snapshot captures the state of files at that moment, and because snapshots are taken periodically and retained for a time, the drive can hold several earlier versions of a file, each tied to the date its snapshot was taken.

The examination can mount these snapshots and recover the earlier versions of documents in scope. The value is in showing change over time: where a current document differs from an earlier version in a shadow copy, the report can set out what the document held at the earlier date and what it holds now, so an alteration, a deletion of a line, a change of a figure, a removal of an item, can be shown rather than merely alleged. In a finance dispute or a question of a document's integrity, that is often exactly what is needed.

The honest limit is availability. Windows manages shadow copies automatically, and they are not always present: the feature may be turned off, snapshots may have been aged out, or they may be sparse. So shadow copies are a valuable source when they exist, capable of showing what a file said at an earlier date, but not one that can be relied on to be there. The report sets out which snapshots existed, what they held for the documents in scope, and where the source was absent.

What it records, and what it means.

Describe your situation →
What is recorded Where it comes from What it shows, and does not
Earlier versions of a documentVolume Shadow Copy snapshotsThe content at the snapshot date; where snapshots exist
What a document said before a changeThe earlier version against the currentThe difference; not why it was changed
When each earlier version dates fromThe snapshot's own dateThe snapshot date; not every intermediate change
Whether earlier versions survive at allThe snapshots present on the driveWhat exists; snapshots may be absent or sparse

From the exhibit arriving to the report.

Work we have closed →
01

The first conversation, and the authority check Free

Tell us the situation, who owns the device, and what you need to know. We tell you whether it is a job we can take on, what authority we will need, and whether the standard report answers your questions or an expert report is called for. That conversation is free, and some enquiries end there, because we will not take work we cannot lawfully or honestly do.

FreeOwner-only; authority established firstThe honest answer about what is possible
02

Imaging behind a write blocker, and the hashes

When the exhibit arrives, your authority is checked, the device is logged and photographed, and the drive is connected through a hardware write blocker and imaged bit for bit. MD5 and SHA-256 hashes of the source and the image are computed and verified, so the copy is provably identical. Nothing is examined on the original; every later step is done on the verified image.

Bit-for-bit, behind a write blockerMD5 and SHA-256, verifiedThe original never altered
03

The examination, on the image

The image is examined for the artefacts your questions turn on: USB device history, files opened from removable media, cloud and webmail activity, deleted files and the Recycle Bin, the USN journal, program execution, email, document metadata, shadow copies, and a timeline. Findings that matter are confirmed in a second tool. The work is scoped to what you asked; material outside the scope is not reproduced.

Scoped to your questionsConfirmed in a second toolPrivate material filtered out
04

The report

The standard forensic report sets out the exhibit and its condition, the integrity record, the tools and method, and the findings by category, with a timeline, the limitations, and factual conclusions, as a self-contained report with its chain-of-custody and case-log reports. It is written in plain terms, keeps fact separate from any comment, and is suitable for internal decisions, HR processes, negotiations and solicitors. Where you need opinion evidence for court, an expert report is quoted.

Factual, tool-generated, self-containedChain-of-custody and case-log reports5–10 working days

From the bench

  • Preserve the drive promptly; shadow copies are aged out over time, so the earlier versions you need may not survive long.
  • Tell us which documents matter; shadow copies are searched for the documents in question, not every file.
  • Do not assume they exist; they are valuable when present, but the feature can be off or the snapshots gone.

A shadow copy can hold a document as it was weeks or months ago, so a change to a budget or a schedule can be shown rather than merely alleged.

What helps, and what harms.

Do this much first

  • Stop using the device and keep it powered off
  • Preserve it as it is; record who has held it
  • Gather your proof of ownership or authority
  • Tell us the questions you need answered

What sets us back

  • Letting IT or anyone open it to have a look
  • Reinstalling, wiping or running recovery software
  • Carrying on using the device
  • Assuming artefacts prove who was at the keyboard
We examine devices only for the people and organisations with lawful authority over them. Before any work begins we ask for proof that the device is yours, or documented authority to have it examined: proof of ownership, a director's or HR letter for a company device with the lawful basis, a solicitor's instruction, a court order, or an executor's grant. It is a condition of the work, not a formality, and it is what keeps the examination on the right side of the Computer Misuse Act 1990. We will not access another adult's device or accounts without their consent or a court order, we will not install monitoring software or bypass anyone's security, and we do not undertake covert surveillance. A device with no proof of authority is returned unexamined.

Questions answered before you instruct.

Can you show what a document said before it was changed?

Where Windows kept a Volume Shadow Copy from before the change, yes. The examination recovers the earlier version from the snapshot and the report sets out what the document held at the earlier date and what it holds now, so a change can be shown. The limit is that shadow copies are not always present.

What are Volume Shadow Copies?

They are point-in-time snapshots that Windows takes of a drive, used by features like System Restore and backup. Each can contain earlier versions of files as they were when the snapshot was taken, which lets an examination recover a document as it was weeks or months ago, where the snapshots survive.

Will there always be earlier versions to recover?

No. Windows manages shadow copies automatically, and they may be turned off, aged out or sparse, so they cannot be relied on to be present. They are a valuable source when they exist. The report sets out which snapshots were there and what they held, and is clear where the source was absent.

Can you compare the old and new versions?

Yes, where an earlier version exists. The report can set out the earlier content and the current content of a document in scope so the difference is visible, which is often what matters in a finance dispute or a question of a document's integrity.

What does it cost?

Shadow copy examination is part of the standard forensic report, £800 + VAT for a one-disk system. The first conversation is free.

The record is on the device; preserve it first.

The first conversation is free. Tell us the situation and who owns the device, and we will tell you what the evidence can show, what it cannot, and whether we can take it on. Until then, stop using the device and preserve it as it is.

0800 6890668