Taking instructions now — the first conversation is freeExhibits posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
FDRForensic Data Recovery 0800 6890668 Price my job
FDR / Sample reports / Departing employee: company laptop

Illustrative — synthetic data · Departing employee · company laptop · USB · cloud · deletions

Sample report: a departing employee's company laptop. What the laptop recorded in the final week, set out as fact.

Northgate Fittings Ltd suspected that a director who had resigned to join a competitor had taken confidential client and pricing information before leaving. The company instructed an examination of the laptop it had issued to him. This illustrative report shows how the standard report sets out what the device recorded, and what it could not establish.

Standard report£800 + VAT, one diskSynthetic dataFactual findings only

Rather talk it through? An engineer answers the bench line
0800 6890668

Illustrative — synthetic data. This is an example of the standard forensic report, written to show its structure and depth. The people, companies, serial numbers, hashes and dates are invented, and the hashes are shortened placeholders, not real values. A real report is a self-contained HTML or PDF document produced in OSForensics, with its chain-of-custody and case-log reports attached, and findings confirmed in a second tool.

1. Scope and the questions asked.

The company asked: (a) whether removable storage was connected to the laptop between 1 May and 12 June 2026 and, if so, what; (b) whether company documents were opened from removable media or uploaded to personal cloud or webmail services; (c) whether files were deleted in the final days; and (d) for a timeline of the last week of use. The examination was of the device only; no accounts belonging to the user were accessed.

2. Authority and lawful basis.

The laptop is company property, confirmed in writing by the managing director, with the lawful basis stated as the company's legitimate interest in protecting its confidential information. The company's acceptable-use and monitoring policy, supplied, tells staff that company devices may be examined. Personal material encountered outside the scope, two folders of family photographs and personal banking bookmarks, was not opened beyond what was needed to classify it and is not reproduced.

3. Exhibit and integrity.

Item As recorded
Condition on receiptSealed bag NF-00231, intact; powered off; no damage
Drive512 GB NVMe SSD; serial recorded in the case log
Write blockerHardware write blocker throughout acquisition
ImageE01, acquired with FTK Imager; log at Appendix A
MD5 (placeholder)3f2a…c91d — source and image match
SHA-256 (placeholder)9b71…e042 — source and image match
Re-verified16 June before analysis; 22 June before issue; unchanged
ResealedSeal FDR-00892 on return

4. Tools and method.

OSForensics for User Activity, Deleted Files Search, the $UsnJrnl, Prefetch, event log and registry viewers, and the case report; Autopsy to confirm the USB device list and the jump-list findings in a second tool; FTK Imager for acquisition and verification. The system clock was set to GMT Standard Time; all times are UTC, with local time one hour later during British Summer Time. The drive is an SSD that reports TRIM support, which limits deleted-file recovery, as section 7 explains.

5.1 Removable storage connected.

Three USB storage devices are recorded in the registry and the Partition/Diagnostic event log. Two were first connected in the final four days of the period: a Kingston flash drive on three evenings, and a Seagate portable hard disk once, for just over two hours.

Table 5.1: Removable storage connected

Device as recorded Serial (redacted) First connected Last connected
SanDisk Ultra USB 3.0, 64 GBAA02…7F2024-11-03 09:122025-02-19 14:05
Kingston DataTraveler 3.0, 128 GB1C6F…B32026-06-09 18:272026-06-11 19:03
Seagate Expansion portable, 2 TBNA9…K42026-06-11 18:402026-06-11 20:51

5.2 Files opened from removable media.

Thirty-one jump-list, shortcut (LNK) and shellbag entries reference paths on volumes whose serials match the Kingston drive (E:) and the Seagate drive (F:). The folder names correspond to folders in the user's company OneDrive. Representative entries follow; the full list is at Appendix D.

Table 5.2: Files opened from removable media

Time (UTC) Artefact Target Volume
2026-06-09 18:31ShellbagE:\NF Clients 2026\Kingston
2026-06-09 18:33LNKE:\NF Clients 2026\Tender - Harbourside.xlsxKingston
2026-06-11 18:44ShellbagF:\Backup June\Pricing\Seagate
2026-06-11 19:02Jump list (Excel)F:\Backup June\Pricing\Master Price List 2026.xlsxSeagate

5.3 Cloud and webmail activity.

A personal Dropbox client was installed on 10 June 2026 at 19:14 UTC (installer in Downloads; installation event in the Application log). Its logs record about 1.8 GB uploaded across 10 and 11 June; file names are not stored in those logs. Browser history shows sign-ins to a personal webmail service on 9, 10 and 11 June, and three visits to a file-transfer website between 20:10 and 20:38 UTC on 11 June, with no matching downloads. That pattern is consistent with uploading, but it does not show what, if anything, was sent.

5.4 Deleted files.

The USN journal records 412 delete operations under the user's account on 12 June 2026 between 15:50 and 16:30 UTC, in the local Documents\NF folder and the OneDrive folder; the Recycle Bin was emptied at 16:31. Deleted Files Search recovered 58 of the 412 files with a quality indicator above 80; the remainder returned zeros, consistent with TRIM on an SSD. Recovered files were hashed and supplied; none was opened beyond confirming its type.

6. Timeline extract.

Time (UTC) Event Source
09 Jun 18:27Kingston drive connectedRegistry, event log
09 Jun 18:31–18:52Folders browsed, files opened on E:Shellbags, LNK, jump lists
10 Jun 19:14Personal Dropbox client installedApplication log, Downloads
10 Jun 19:20–22:05Dropbox upload activityClient logs
11 Jun 18:40Seagate drive connectedRegistry, event log
11 Jun 20:10–20:38File-transfer site visitedBrowser history
12 Jun 15:50–16:30412 files deletedUSN journal
12 Jun 16:31Recycle Bin emptiedUSN journal
12 Jun 16:58ShutdownSystem log

7. Limitations.

The artefacts show that the devices were connected and that the named files and folders were opened or existed on them under the user's account. They do not show who was at the keyboard, and Windows does not log copy operations, so they do not show that files were copied or later used. The cloud and transfer-site activity shows volume and timing, not content. TRIM has removed most deleted file content. The system clock was checked against the examination workstation and found accurate to within one minute.

8. Conclusions, as fact.

Within the scope: two removable storage devices were first connected in the final four days; folders and files bearing the company's client, pricing and quote folder names were opened from them; a personal cloud client was installed and uploaded about 1.8 GB over two evenings; a file-transfer site was visited; and 412 files were deleted and the Recycle Bin emptied on the final afternoon, 58 of which were recovered.

9. Exhibits and appendices.

Exhibits: E1 laptop, returned resealed; E1/IMG1 forensic image, retained encrypted for 90 days; E1/REC recovered files, supplied on encrypted media. Appendices: A acquisition log; B tool versions and case-log extract; C recovered files with hashes; D removable-media artefacts in full; E glossary.

This is what the standard report looks like.

The standard forensic report for a one-disk system is £800 + VAT. Tell us the situation and who owns the device, and the first conversation will tell you whether it answers your questions.

0800 6890668