Digital forensics
A computer keeps a record of how it was used.
Which USB devices were plugged in, and when. Which files were opened, including files that no longer exist. Who logged on, what was deleted, what was synced to a cloud account, whether the whole machine was wiped. We examine computers and drives for exactly these questions, without changing a byte of what we examine, and set out the answers in a written report. The work is done in Sydney, and devices arrive from anywhere in Australia by tracked courier.
What a computer can be shown to have been used for
The work goes by several names: digital forensics, computer forensics, cyber forensics. Under all of them the client’s question is the same, what was this machine used for, and how much of that can be shown. The answer is usually more than people expect. A computer in ordinary use keeps quiet records of its own activity, most of them outlive the events they describe, and reading them without disturbing them is a discipline of its own.
- USB storage devices. Which ones were connected, identified by make, model and serial number, with dates and times.
- Files opened, and when. Windows keeps lists of opened documents in several places, and a record of opening a file often outlives the file itself.
- Logons and logoffs. Which account signed in, when, for how long, and whether it happened at the keyboard or over the network.
- Deleted files, with their context. Recovered with original folder paths and timestamps where the data survives, which is what separates forensic data recovery from a bare undelete.
- Browser history and downloads. Sites visited, searches run, files downloaded.
- Cloud sync activity. Traces left by OneDrive, Dropbox and Google Drive: which accounts were connected, and signs of what moved through them.
- Wireless networks joined. With dates, which matters when where a laptop has been is in question.
- Whether it was wiped, and when. A wipe removes data and leaves a shape behind: an operating system installed the week before handback, logs that begin the day after a resignation.
None of these records is exotic. They exist on the machine in front of you now. The value of the examination is in reading them without changing them, tying them together, and claiming no more than they support.
The situations that bring this work in
- An employee has left, and work seems to have left with them. Client lists, quotes or drawings turning up where they should not be, and a handed-back laptop that holds the USB history and file activity for the weeks that matter.
- The copy question. A business that needs to establish whether files went onto a USB stick before a resignation, and would rather know than guess.
- Family law and estate matters. Where what a computer was used for, or what accounts and assets its records point to, is in question.
- Insurance disputes. Where the condition or use of a device is contested and the answer needs to be shown in writing, with its method attached.
- Disposal and sale. Confirming a machine was wiped before it left, and holding a dated report that says so.
- IT providers and law firms. Who need the technical examination done with custody and method intact, reported so it can be handed on.
One rule sits under every situation above. Nothing we do is covert: no monitoring of people, no watching live activity, no accessing accounts, no recovering someone else’s data. Every job on this page is the open examination of a device the client is entitled to have examined.
When the record that matters is camera footage rather than computer activity, the examination is a different one, with its own page: CCTV and DVR footage recovery →
How the examination is done
The examination never touches the original data. The device is read once through a write blocker, hardware between the device and the workstation that lets data out and nothing in, and that read produces a complete copy, a forensic image. Every search, every recovered file and every finding after that point comes from the image. The original is stored, unchanged, until it goes back to you.
As the image is made, a SHA-256 hash is computed for the data read, and the same calculation is run again afterwards to verify the copy. The point of the number is plain: at any later date, the copy can be shown to match what the device held on the day it was read.
Custody is documented from the moment the device changes hands. Transfers are signed and dated, the device is identified by make, model and serial number, and when it travels by tracked courier, the tracking forms part of the same record. If the device has a story before it reaches us, who held it and when, that goes in the record too.
Before any examination starts, we ask you to confirm in writing that you own the device or have authority to have it examined. That is our practice on every job, and it protects two things: you, and the findings.
The written report
The report is the deliverable, and it is written to be read. It sets out what was asked, what was received and in what condition, the method used, what was examined, what was found, and what could not be established. Findings are tied to the records they come from, so a reader can trace every statement back to its source.
The last item on that list carries as much weight as the rest. Where the evidence runs out, the report says so in the same plain terms as the findings, because anyone weighing the document needs both.
Reports are written in plain English with the technical trail kept, so a director, an insurer or a solicitor can follow the reasoning without a translator.
What cannot be established
Four walls come up again and again, and you will hear about them at the assessment, before anything is spent.
Encrypted volumes without keys stay closed. We work with the passwords and keys you can provide. Without them, an encrypted volume is a fact to report, and nothing more.
A clean result has limits. If no trace of copying is found, the report says no trace was found. It cannot promise the copying never happened, and it will not pretend to.
Overwritten data does not come back. Space that has been reused holds only what reused it, and no tool changes that.
Modern SSDs erase deleted files on their own. Often within minutes of the deletion, which means the deleted-file picture on an SSD is frequently thin or gone. Why that happens is its own page: SSD data recovery →
Expert evidence, and where this service stops
The reports described on this page are technical examination reports: method, custody, findings, limits. They are written for businesses, insurers, solicitors and private clients who need to know what a device holds, and most matters need exactly that and nothing further.
Some matters need more. If a report is to be tendered as expert evidence, with its author available for cross-examination, that is a different engagement with its own requirements, and it has to be framed that way from the first hour. Say so at the start, so the work can be scoped for it, or declined. Your solicitor should be part of that conversation before the examination begins, because how findings will be used shapes how the work is done.
One person does this work, the same person you speak to at the assessment, with more than twenty years in IT and data recovery behind the method above. You will not be handed between departments, and the report’s author is never a stranger to the device it describes.
What it costs
Examination and reporting is $195 an hour. The assessment that starts every matter is free: you describe the situation, we say whether an examination can answer the question you are asking, and what it is likely to involve. Scope and estimate are agreed in writing before the first billed hour, and the estimate does not stretch without your agreement.
Hourly is the honest structure here, and it is the opposite of how the recovery services on this site are priced. A recovery has a defined outcome, so it carries a fixed quote, and no recovery means no fee. An examination is investigative: nobody can promise what a record will show before reading it, so a fixed price for an outcome would be a number made up in advance. The hours are the deliverable, and the report is where they went.
General information about what device examination can and cannot establish, current at the time of writing. It is not legal advice, and whether findings can be used in any proceeding depends on facts and rules this page cannot know. For anything contested, talk to a solicitor before the examination starts.
Common questions
Can you tell if files were copied to a USB drive before someone resigned?
Often, with an honest limit attached. Windows records which USB storage devices were connected, identified by make, model and serial number, with dates and times, and separately records which files and folders were opened and when. What it rarely keeps is a direct record of the copy itself. The usual finding is a pattern: a device connected in a certain window, and the files in question opened inside it. The report sets out that pattern exactly, and claims nothing beyond it.
Do you monitor employees or carry out surveillance?
No. Nothing we do is covert and nothing we do watches anyone. The work is the examination of a device after the event: a laptop the business owns, a computer you are entitled to have examined, handed over openly, with that authority confirmed in writing before anything starts. We do not install monitoring software, access anyone's accounts, or recover data for a person who has no right to it.
Can the report be used in court?
That is a question for your solicitor, and the useful starting point is what the report is. It documents the method, the chain of custody, the hash verification of the working copy, what was found, and what could not be established. Whether your matter needs a report tendered as expert evidence, with the author available for cross-examination, is a separate question with its own requirements. If it does, say so at the start: it changes how the work is scoped, and it may be an engagement we decline.
What does a digital forensic examination cost?
$195 an hour, with a free assessment first. You describe the situation, we tell you whether an examination can answer the question you are asking, and you receive a scope and estimate in writing before any billed work starts. It is hourly because the work is investigative: what a device's records hold cannot be known before they are read, so a fixed outcome price would be a guess dressed up as a quote. Extending past the agreed estimate is your call, made in advance.