Taking instructions now — the first conversation is freeExhibits posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
FDRForensic Data Recovery 0800 6890668 Price my job
FDR / What we examine / Laptops and desktops

Laptops · desktops · Windows · macOS · Linux · the drive · user activity

Laptop and desktop forensics. The computer someone worked on is the commonest exhibit, and the richest; its drive holds the record.

A laptop or desktop is the exhibit most examinations start with, because it is where people work and so where the evidence of what they did usually sits. We examine the computer's drive, which is the part that holds the data, imaging it behind a write blocker and examining the image for the artefacts a matter turns on: user activity, removable storage, cloud and email, deletions, documents and a timeline. In most cases the drive can be removed and sent on its own, which is all we need; where it cannot, the whole machine can come in.

Owner-only, authority requiredFree first conversationStandard report £800 + VATImaged first, never the original

Rather talk it through? An engineer answers the bench line
0800 6890668

Before anything else: stop using the device, and do not let anyone have a look at it. Every time a computer is switched on and used, the very artefacts an examination relies on, the timeline, the recently-opened lists, the deleted-file space, are overwritten a little more. Do not reinstall, do not run recovery software, do not let IT open it to check, and keep it powered off. Preserve it as it is, record who has held it, and send it with the authority documents we ask for. If proceedings are contemplated, the duty to preserve evidence has already begun.

How a computer is examined.

What we examine is the computer's drive, a hard disk, SSD or NVMe module, because that is where the data and the artefacts live. In most desktops and many laptops the drive can be removed and sent on its own, which is all the examination needs; where a laptop's storage is soldered to the board, the whole machine comes in. Tell us which on the form, and if you are not sure, we will guide you.

The drive is imaged bit for bit behind a write blocker and hashed, and the examination runs on the image. Windows is the commonest system, and the artefacts, USB history, jump lists, the change journal, Prefetch, shadow copies, are richest there; macOS keeps its own equivalents (unified logs, FSEvents, Spotlight) and Linux its own, and we examine all three.

What the examination finds is driven by your questions, and the evidence pages set out each category in detail. The result is the standard forensic report: a factual account of what the computer records, with the limits stated.

What to know for this exhibit.

The drive is what mattersThe data and the artefacts live on the drive, so that is what we examine. In most machines it can be removed and sent on its own; where it is soldered in, the whole laptop comes in.
Windows, macOS and LinuxWe examine all three. Windows is richest in artefacts, but macOS and Linux keep their own records of user activity, and we examine those on their own terms.
Imaged, never the originalThe drive is imaged behind a write blocker and hashed, and all work is done on the image. The original is not altered.
The report is shaped to your questionsWhat is examined, and reported, is driven by what you need to know, from the evidence categories set out across this site.

From the exhibit arriving to the report.

Work we have closed →
01

The first conversation, and the authority check Free

Tell us the situation, who owns the device, and what you need to know. We tell you whether it is a job we can take on, what authority we will need, and whether the standard report answers your questions or an expert report is called for. That conversation is free, and some enquiries end there, because we will not take work we cannot lawfully or honestly do.

FreeOwner-only; authority established firstThe honest answer about what is possible
02

Imaging behind a write blocker, and the hashes

When the exhibit arrives, your authority is checked, the device is logged and photographed, and the drive is connected through a hardware write blocker and imaged bit for bit. MD5 and SHA-256 hashes of the source and the image are computed and verified, so the copy is provably identical. Nothing is examined on the original; every later step is done on the verified image.

Bit-for-bit, behind a write blockerMD5 and SHA-256, verifiedThe original never altered
03

The examination, on the image

The image is examined for the artefacts your questions turn on: USB device history, files opened from removable media, cloud and webmail activity, deleted files and the Recycle Bin, the USN journal, program execution, email, document metadata, shadow copies, and a timeline. Findings that matter are confirmed in a second tool. The work is scoped to what you asked; material outside the scope is not reproduced.

Scoped to your questionsConfirmed in a second toolPrivate material filtered out
04

The report

The standard forensic report sets out the exhibit and its condition, the integrity record, the tools and method, and the findings by category, with a timeline, the limitations, and factual conclusions, as a self-contained report with its chain-of-custody and case-log reports. It is written in plain terms, keeps fact separate from any comment, and is suitable for internal decisions, HR processes, negotiations and solicitors. Where you need opinion evidence for court, an expert report is quoted.

Factual, tool-generated, self-containedChain-of-custody and case-log reports5–10 working days

Before you send it

  • Stop using the computer and keep it off; every use overwrites the artefacts an examination relies on.
  • Send the drive, or the whole machine if the drive is soldered in; tell us which, and we will guide you.
  • Do not let IT reimage or reset it; that destroys the evidence.

Windows keeps the richest artefacts, but macOS and Linux hold their own records of user activity, and all three are examined on the same principles.

What helps, and what harms.

Do this much first

  • Stop using the device and keep it powered off
  • Preserve it as it is; record who has held it
  • Gather your proof of ownership or authority
  • Tell us the situation and the questions you have

What sets us back

  • Letting anyone open it to have a look
  • Reinstalling, wiping or running recovery software
  • Carrying on using the device
  • Sending us a mobile phone; they are not examined
We examine devices only for the people and organisations with lawful authority over them. Before any work begins we ask for proof that the device is yours, or documented authority to have it examined: proof of ownership, a director's or HR letter for a company device with the lawful basis, a solicitor's instruction, a court order, or an executor's grant. It is a condition of the work, not a formality, and it is what keeps the examination on the right side of the Computer Misuse Act 1990. We will not access another adult's device or accounts without their consent or a court order, we will not install monitoring software or bypass anyone's security, and we do not undertake covert surveillance. A device with no proof of authority is returned unexamined.

Questions answered before you instruct.

Do you need the whole computer, or just the drive?

Usually just the drive, which holds the data and the artefacts, and in most machines it can be removed and sent on its own. Where a laptop's storage is soldered to the board, the whole machine comes in. Tell us the make and model and we will advise.

Can you examine a Mac or a Linux machine?

Yes. macOS and Linux keep their own records of user activity, different from Windows but examined on the same principles, imaged behind a write blocker and examined on the image. We examine all three systems.

The computer has a login password we do not have. Can you still examine it?

Often, yes, because we examine the drive from a forensic image rather than by logging in, and a Windows or macOS login password does not encrypt the files. Where the drive itself is encrypted with BitLocker or FileVault, we would discuss the recovery key or password with you.

What will the examination find?

What your questions call for, from the evidence categories set out across this site: removable media, cloud and email, deletions, documents, a timeline and more. The report is a factual account of what the computer records, with the limits stated.

What does it cost?

The standard forensic report for the one computer is £800 + VAT. The first conversation is free.

Preserve it, and let us image it first.

The first conversation is free. Tell us the exhibit and the situation, and who owns it, and we will tell you what can be examined, what authority we need, and whether we can take it on. Until then, stop using it and preserve it as it is.

0800 6890668