Digital Forensics

Digital forensics is the preserved, repeatable examination of computers, servers and storage to establish what actually happened: what was made, moved, copied, deleted or hidden, reported so a court can rely on it.

Every examination runs the same way here, under the DDD Method. Detect: the evidence is imaged before it is read, verified by hash, originals untouched. Document: every source and step recorded so another expert can repeat and test the work. Demonstrate: findings in plain language with referenced exhibits, aligned with the Rules of the High Court (Order 38) where expert evidence is required. Our reporting and oral evidence have been given to the courts of Hong Kong and Singapore.

The work covers desktops, laptops and servers, NAS and DAS storage, backup tapes and the systems around them: user activity and file-movement timelines, USB and exfiltration traces, deleted material where it survives, and the difference between what a document says and what its metadata admits.

You suspect what happened. We establish what the evidence shows, and we report it the same way whether it helps or hurts, because that is what makes it evidence.