Computer forensics that reconstructs what actually happened.
A computer remembers far more than its user intends. We examine Windows and Apple Mac systems to establish user activity, file movement and timelines, and we report it in a form that survives challenge.
What the examination covers
Most instructions turn on a small set of questions. Who used the machine, and when. Which files were opened, copied, renamed or destroyed. What arrived and left by USB, email or cloud. Whether the operating system's own records support or contradict an account someone has given. We answer those questions from the artefacts the system keeps about itself: link files, jump lists, registry records, USB history, shellbags, browser and file-activity traces, event logs and the file system's journals.
Examination is performed on a verified, hash-validated image, never the original. Where the machine has been used since the events in question, we say plainly what that use has cost the record. An honest account of what the evidence cannot show is part of what makes the rest reliable.
Instructions we commonly take
- Reconstructing a departing employee's final weeks on a company laptop.
- Testing whether a document existed, was edited or was backdated.
- Establishing whether a machine was accessed after hours or by another person.
- Corroborating or challenging an account given in proceedings or an internal inquiry.
Frequently asked
- How long does a computer forensic examination take?
- Imaging is typically completed within a day of receiving the machine. Focused analysis of a single computer usually reports within one to two weeks, depending on the questions and data volume. Urgent preservation can happen same-day.
- Does examining a computer change the evidence?
- No. Analysis is performed on a verified forensic image; the original is preserved untouched. That separation is what allows findings to be reproduced and tested by another expert.
Speak to the consultant who will run the work
Instructions are led by Alan Jeffries, Principal Consultant. The first discussion is confidential, carries no fee, and often changes what a client decides to do next. Call +852 5808 1071, message us on Signal, or use the case review form.
Every engagement runs under the DDD Method: Detect. Document. Demonstrate.