Digital & computer forensics
Forensic examination of Windows and Apple Mac computers and laptops to establish user activity, file handling and timelines.
Forensic preservation, investigation, analysis and expert reporting of electronic evidence, handled to a standard that holds up in court and stands up to scrutiny. We act for Hong Kong legal firms, corporates, HR and insolvency teams, and private clients with substantive matters.
Most instructions begin with a concern and a device, an account or a dataset that may hold the answer. Our role is to preserve that evidence properly and report what it does, and does not, demonstrate.
Each instruction is scoped to the matter. We preserve first, analyse methodically, and report in plain English with exhibits that withstand challenge. Each service has a full page: start at the services index.
Forensic examination of Windows and Apple Mac computers and laptops to establish user activity, file handling and timelines.
Examination of iPhone and Android devices for messages, calls, app data, media, location and deleted content, where lawfully authorised.
Defensible collection, processing, de-duplication and review-ready production of electronic documents for discovery.
Investigation of mailbox activity, Microsoft 365 and Google Workspace audit logs, SharePoint, OneDrive and Dropbox access and sharing.
Independent expert reports and exhibits prepared to the standard required for legal proceedings, with the expert's overriding duty to the court paramount.
Rapid, evidence-led response to suspected intrusion, ransomware or data loss to establish scope, cause and impact.
Investigation of suspected data exfiltration, IP theft, policy breaches and misuse on company systems and accounts.
Recovery and interpretation of deleted, hidden or fragmented data and the artefacts that reveal prior activity.
Verified, hash-validated acquisition and preservation of devices and data, with full documentation from seizure to report.
Lawful open-source intelligence and online investigation to corroborate findings and support due diligence or dispute matters.
Where a matter involves concerns about covert devices or unauthorised monitoring, we provide an electronic privacy audit alongside the digital investigation.
Most matters cross several of these areas. Describe the situation and we will tell you what is realistically achievable, and what it would involve.
Request a case reviewElectronic evidence is fragile. Continued use, automatic syncing, log rotation and remote wiping can overwrite or destroy it within hours or days. The earlier evidence is preserved, the more can be recovered and relied upon.
Do not switch on, log into, reset, "have a quick look at" or run software against the device or account. Well-intentioned internal checks frequently overwrite the very evidence in question. Isolate the item and speak to us before anything else.
An employee has left or is leaving and you suspect data has been taken.
Signs of intrusion, ransomware, fraud or account compromise.
Proceedings are likely and electronic evidence must be preserved now.
A phone, laptop or drive has been recovered and must be handled correctly.
A court-imposed or commercial deadline requires rapid, defensible work.
Cloud or email access remains open and ongoing activity risks the evidence.
Every instruction runs the same six steps under one discipline: Detect. Document. Demonstrate. Detect what the evidence holds. Document every step so it can be tested. Demonstrate the findings in a form a court can rely on.
Every step is recorded. This is what makes findings defensible and repeatable, and what distinguishes forensic work from ordinary IT support or data recovery.
We listen to the situation, identify the relevant data sources and advise on immediate preservation, at no obligation and in confidence.
We confirm your lawful authority over the device or account, agree the scope and objectives, and set out the approach and estimate in writing.
We create verified, hash-validated forensic images and preserve cloud and account data, maintaining an unbroken chain of custody throughout.
We process and examine the preserved data using repeatable methods, focusing on the questions the matter actually turns on.
We report findings in plain English with referenced exhibits and, where instructed, independent expert opinion suitable for the court.
We support discovery, respond to questions, assist with further work and, where required, provide witness evidence.
Subject to lawful authority and technical feasibility, we acquire and analyse a wide range of sources, frequently combining several to build a complete picture.
Findings are only as useful as their defensibility. Our work is built on principles that allow it to be relied upon and, if necessary, challenged in proceedings before the Hong Kong courts:
We provide forensic and technical evidence, not legal advice. Where the legal position, authority or consent is uncertain, you should obtain advice from a qualified Hong Kong legal practitioner. We will tell you when this is advisable.
We act only on lawful instructions where ownership, authority or consent is established. We do not assist with unauthorised access, device unlocking without authority, or covert access to third-party accounts.
Anonymised composites of typical instructions. Details are altered and combined to protect confidentiality; the pattern of each matter is reported faithfully.
Full casework, including the matters that made the practice →
A focused first conversation saves time and cost. Having the following to hand lets us advise quickly on feasibility, scope and urgency. You do not need every answer. Tell us what you can.
What type of device or account is involved: laptop, phone, email, Microsoft 365, drive or other.
Your position regarding the item: do you own it, control it, or have lawful authority or consent to examine it?
Whether the device or account is physically and logically accessible, and whether you hold passcodes or credentials.
Relevant dates: when events occurred, when concerns arose, and any deadlines that apply.
A short, factual summary of the situation and your concern.
The question the evidence must answer: the issue the matter turns on.
Whether legal or disciplinary proceedings are active, contemplated or not yet decided.
How time-critical the matter is, and whether evidence may currently be at risk.
Where the parties, devices and data are located, particularly for cross-border matters.
The practice is led by Alan Jeffries, Principal Consultant, whose work spans digital forensics, eDiscovery, expert witness services and technical surveillance countermeasures across Hong Kong and Asia-Pacific. You can verify the practice and the principal before you write to either: Alan Jeffries on LinkedIn.
The consultant who scopes your matter handles it. Findings are reported with the expert's overriding duty to the court paramount, and adverse findings are reported plainly. Credentials, prior forum experience and references are available to instructing counsel under confidentiality.
Direct answers to the questions clients and advisers most often ask. For anything specific to your matter, request a confidential case review.
Digital forensics is the structured identification, preservation, analysis and reporting of electronic evidence so it can be relied upon in legal, regulatory or internal proceedings. It applies repeatable, documented methods to devices, accounts and data while maintaining chain of custody.
A digital forensic expert preserves data forensically, analyses it to establish what happened, and produces a clear report and exhibits. Where instructed, the expert provides independent opinion evidence and supports disclosure, litigation or internal investigations.
Often, yes. Deleted files, fragments and traces of activity can frequently be recovered from unallocated space, journals and metadata, depending on the device, how it has been used and how quickly it was preserved. Continued use reduces what can be recovered.
Yes. We forensically examine iPhone and Android devices for messages, call logs, app data, location artefacts, media and deleted content, subject to lawful authority and the technical condition of the device.
Yes. We examine company devices and accounts for evidence of data exfiltration: USB transfers, cloud uploads, mass downloads, file copying and email forwarding, and report findings for HR, legal or court use.
Yes. With proper authority we review Microsoft 365 audit logs, mailbox activity, SharePoint and OneDrive access, sign-in records and sharing events to establish who accessed or moved what, and when.
Yes. We prepare clear, defensible reports for legal proceedings, including exhibits and, where instructed, independent expert opinion compliant with the Rules of the High Court (Order 38) and the Code of Conduct for Expert Witnesses, including the expert's overriding duty to the court.
Forensic imaging is the creation of a verified, bit-for-bit copy of a device or data source, so the original is preserved and analysis is performed on the copy. The image is hash-verified to demonstrate its integrity.
Chain of custody is the documented record of who handled an item of evidence, when, and what was done to it, from acquisition to reporting. It demonstrates the evidence has not been altered and supports admissibility.
As soon as possible. Evidence is overwritten through continued use, automatic syncing, log rotation and remote wiping. Early preservation protects recoverability and should ideally precede any internal examination.
Often, yes. WhatsApp and similar chat data, including some deleted content, may be recoverable from a device or backup where there is lawful authority and the data has not been overwritten or securely erased.
It depends on the device. A passcode, password or account credentials significantly improve access and the range of recoverable data. We advise on the options based on the specific device and your lawful authority over it.
Sometimes, where there is appropriate authority, consent or another lawful basis. Personal devices raise additional consent and privacy considerations under the Personal Data (Privacy) Ordinance, so we confirm the legal position and scope before any examination.
Yes. We support solicitors with forensic preservation, eDiscovery processing, targeted review, discovery of electronic documents and expert evidence, working to the instructions and procedural requirements of the matter.
Do not continue using, switching on, logging into, resetting or examining the device or account, and do not delete or move data. Continued activity can overwrite or destroy evidence. Preserve the item and speak to us first.
Cost depends on the number and type of data sources, the volume of data, the urgency and whether expert reporting or court attendance is required. We provide a scoped estimate after an initial confidential discussion.
Yes. We accept international instructions and provide Hong Kong-facing forensic expertise for cross-border matters, subject to applicable law, data transfer requirements and the practicalities of acquisition.
Begin with a confidential case review. Tell us the device or data source, your authority over it, the key dates, what happened and what you need to prove or disprove. We then confirm scope, authority and next steps in writing.
D3Forensics Limited is a court-aware digital forensics and expert witness consultancy based in Hong Kong and accepting international instructions. It preserves, investigates, analyses and reports electronic evidence to a defensible standard for legal firms, corporates, HR and insolvency teams, and private clients with serious matters.
Tell us about the matter in confidence. We will advise on what is achievable, what to preserve immediately, and the likely approach, with no obligation.
Do not alter the device before speaking to us. Do not switch it on, log in, reset it or run software against it. Preserve it as it is. Early action protects the evidence.
Telephone+852 5808 1071
Emailinfo@d3forensics.com
OfficeUnit 215, Hundsun International Centre,
44 Heung Yip Road, Wong Chuk Hang, Hong Kong
Service regionsHong Kong · Asia-Pacific · United Kingdom
HoursMonday–Friday · urgent matters by arrangement
Enquiries are treated in strict confidence. Information shared at this stage is used only to assess and respond to your matter, and personal data is handled in accordance with the Personal Data (Privacy) Ordinance (Cap. 486). We are happy to operate under your firm's engagement terms where applicable.