Ordinary recovery asks whether the data came back. Forensic work asks a harder question — can you demonstrate, later and under challenge, that what you produced is exactly what was on the device and that you altered nothing.
The technical work overlaps heavily. What differs is that every step is blocked from writing, hashed to prove integrity, and documented so the chain holds up months later.
Connecting a drive to a computer normally is not passive — the operating system may mount it, update access times, write recovery files, or index it. A hardware write blocker sits between the drive and the workstation and physically refuses write commands, so the source can be read completely while remaining provably unaltered.
Everything afterwards happens on the image rather than the original, which is both good forensic practice and good recovery practice for the same underlying reason: the original only has to survive being read once.
Immediately after imaging, a cryptographic hash — typically SHA-256 — is computed across the source and the image. If the two match, the copy is bit-for-bit identical. That hash is recorded and re-verified at each stage, so if anything alters by a single bit at any point, the mismatch is obvious and demonstrable.
This is what makes findings defensible. Not the sophistication of the analysis, but the ability to show that the material analysed is provably identical to what was seized.
Once working from a verified image, the interesting material is usually in what an ordinary user never sees: USB connection records in the registry showing which devices were attached and when; link files and jump lists showing what was opened; shellbags recording folder access; file system timestamps distinguishing creation from modification from access; and deleted material still present in unallocated space.
In a typical departing-employee case those artefacts together establish which external device was connected, when, and what was accessed around that time — often more informative than the files themselves.
UK work follows the ACPO principles for digital evidence: no action should change the data; where that is unavoidable the person must be competent to explain why; an audit trail must exist such that an independent third party could repeat the process and reach the same result. In practice that means signed exhibit records, logged handling, recorded hashes and a report written to be read by non-technical people.
Forensic work starts from £800 +VAT and is quoted after a scoping discussion. It is not offered on a no-fix-no-fee basis, and carries a 50% deposit — because the analysis has value whatever it concludes, including when it establishes that nothing happened.
Ordinary recovery aims to return your files. Forensic recovery has to prove nothing was altered — so the source is read behind a write blocker, hashed to demonstrate the copy is identical, and every step logged so an independent party could repeat it and reach the same result.
Hardware that sits between the drive and the workstation and physically refuses write commands. It matters because simply connecting a drive normally can mount it, update access times and write files — any of which undermines the evidence before analysis has started.
Often. USB connection records, link files, jump lists, shellbag entries and file system timestamps together show which devices were attached, when, and what was opened around that time. What can be established varies by system and by how much has happened since.
The UK guidance for handling digital evidence: no action should change the data; where change is unavoidable the person must be competent to explain it; and an audit trail must exist such that an independent third party could repeat the process and reach the same conclusion.
From £800 plus VAT, quoted after a scoping discussion. Forensic work is not offered on a no-fix-no-fee basis and carries a 50% deposit, because the analysis has value whatever it concludes — including establishing that nothing improper occurred.