Laptops · desktops · Windows · macOS · Linux · the drive · user activity
Laptop and desktop forensics. The computer someone worked on is the commonest exhibit, and the richest; its drive holds the record.
A laptop or desktop is the exhibit most examinations start with, because it is where people work and so where the evidence of what they did usually sits. We examine the computer's drive, which is the part that holds the data, imaging it behind a write blocker and examining the image for the artefacts a matter turns on: user activity, removable storage, cloud and email, deletions, documents and a timeline. In most cases the drive can be removed and sent on its own, which is all we need; where it cannot, the whole machine can come in.
Rather talk it through? An engineer answers the bench line
0800 6890668
How a computer is examined.
What we examine is the computer's drive, a hard disk, SSD or NVMe module, because that is where the data and the artefacts live. In most desktops and many laptops the drive can be removed and sent on its own, which is all the examination needs; where a laptop's storage is soldered to the board, the whole machine comes in. Tell us which on the form, and if you are not sure, we will guide you.
The drive is imaged bit for bit behind a write blocker and hashed, and the examination runs on the image. Windows is the commonest system, and the artefacts, USB history, jump lists, the change journal, Prefetch, shadow copies, are richest there; macOS keeps its own equivalents (unified logs, FSEvents, Spotlight) and Linux its own, and we examine all three.
What the examination finds is driven by your questions, and the evidence pages set out each category in detail. The result is the standard forensic report: a factual account of what the computer records, with the limits stated.
What to know for this exhibit.
From the exhibit arriving to the report.
Work we have closed →The first conversation, and the authority check Free
Tell us the situation, who owns the device, and what you need to know. We tell you whether it is a job we can take on, what authority we will need, and whether the standard report answers your questions or an expert report is called for. That conversation is free, and some enquiries end there, because we will not take work we cannot lawfully or honestly do.
Imaging behind a write blocker, and the hashes
When the exhibit arrives, your authority is checked, the device is logged and photographed, and the drive is connected through a hardware write blocker and imaged bit for bit. MD5 and SHA-256 hashes of the source and the image are computed and verified, so the copy is provably identical. Nothing is examined on the original; every later step is done on the verified image.
The examination, on the image
The image is examined for the artefacts your questions turn on: USB device history, files opened from removable media, cloud and webmail activity, deleted files and the Recycle Bin, the USN journal, program execution, email, document metadata, shadow copies, and a timeline. Findings that matter are confirmed in a second tool. The work is scoped to what you asked; material outside the scope is not reproduced.
The report
The standard forensic report sets out the exhibit and its condition, the integrity record, the tools and method, and the findings by category, with a timeline, the limitations, and factual conclusions, as a self-contained report with its chain-of-custody and case-log reports. It is written in plain terms, keeps fact separate from any comment, and is suitable for internal decisions, HR processes, negotiations and solicitors. Where you need opinion evidence for court, an expert report is quoted.
Before you send it
- Stop using the computer and keep it off; every use overwrites the artefacts an examination relies on.
- Send the drive, or the whole machine if the drive is soldered in; tell us which, and we will guide you.
- Do not let IT reimage or reset it; that destroys the evidence.
Windows keeps the richest artefacts, but macOS and Linux hold their own records of user activity, and all three are examined on the same principles.
What helps, and what harms.
Do this much first
- Stop using the device and keep it powered off
- Preserve it as it is; record who has held it
- Gather your proof of ownership or authority
- Tell us the situation and the questions you have
What sets us back
- Letting anyone open it to have a look
- Reinstalling, wiping or running recovery software
- Carrying on using the device
- Sending us a mobile phone; they are not examined
Questions answered before you instruct.
Do you need the whole computer, or just the drive?
Usually just the drive, which holds the data and the artefacts, and in most machines it can be removed and sent on its own. Where a laptop's storage is soldered to the board, the whole machine comes in. Tell us the make and model and we will advise.
Can you examine a Mac or a Linux machine?
Yes. macOS and Linux keep their own records of user activity, different from Windows but examined on the same principles, imaged behind a write blocker and examined on the image. We examine all three systems.
The computer has a login password we do not have. Can you still examine it?
Often, yes, because we examine the drive from a forensic image rather than by logging in, and a Windows or macOS login password does not encrypt the files. Where the drive itself is encrypted with BitLocker or FileVault, we would discuss the recovery key or password with you.
What will the examination find?
What your questions call for, from the evidence categories set out across this site: removable media, cloud and email, deletions, documents, a timeline and more. The report is a factual account of what the computer records, with the limits stated.
What does it cost?
The standard forensic report for the one computer is £800 + VAT. The first conversation is free.
Preserve it, and let us image it first.
The first conversation is free. Tell us the exhibit and the situation, and who owns it, and we will tell you what can be examined, what authority we need, and whether we can take it on. Until then, stop using it and preserve it as it is.