Call us — 01865 593000
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
Forensics · how it works

Forensic recovery has to prove nothing changed.

Ordinary recovery asks whether the data came back. Forensic work asks a harder question — can you demonstrate, later and under challenge, that what you produced is exactly what was on the device and that you altered nothing.

Write-blocked imaging
Hashed and verified
From £800 +VAT
// the short version

Recovery proves the data. Forensics proves the process.

The technical work overlaps heavily. What differs is that every step is blocked from writing, hashed to prove integrity, and documented so the chain holds up months later.

Hash
Proves integrity
ACPO
UK principles
Log
Every step
£800
From, +VAT
×The most common way evidence is spoiled is by someone looking at it first. Booting the machine, opening files to check, or plugging the drive in to see what is there all change timestamps and can trigger writes. If a device may become evidence, stop using it and hand it over as it is.
// write blocking

Reading without touching.

Connecting a drive to a computer normally is not passive — the operating system may mount it, update access times, write recovery files, or index it. A hardware write blocker sits between the drive and the workstation and physically refuses write commands, so the source can be read completely while remaining provably unaltered.

Everything afterwards happens on the image rather than the original, which is both good forensic practice and good recovery practice for the same underlying reason: the original only has to survive being read once.

// hashing

The number that proves it.

Immediately after imaging, a cryptographic hash — typically SHA-256 — is computed across the source and the image. If the two match, the copy is bit-for-bit identical. That hash is recorded and re-verified at each stage, so if anything alters by a single bit at any point, the mismatch is obvious and demonstrable.

This is what makes findings defensible. Not the sophistication of the analysis, but the ability to show that the material analysed is provably identical to what was seized.

// what analysis finds

Artefacts that survive deletion.

Once working from a verified image, the interesting material is usually in what an ordinary user never sees: USB connection records in the registry showing which devices were attached and when; link files and jump lists showing what was opened; shellbags recording folder access; file system timestamps distinguishing creation from modification from access; and deleted material still present in unallocated space.

In a typical departing-employee case those artefacts together establish which external device was connected, when, and what was accessed around that time — often more informative than the files themselves.

// chain of custody

Documentation that survives challenge.

UK work follows the ACPO principles for digital evidence: no action should change the data; where that is unavoidable the person must be competent to explain why; an audit trail must exist such that an independent third party could repeat the process and reach the same result. In practice that means signed exhibit records, logged handling, recorded hashes and a report written to be read by non-technical people.

Forensic work starts from £800 +VAT and is quoted after a scoping discussion. It is not offered on a no-fix-no-fee basis, and carries a 50% deposit — because the analysis has value whatever it concludes, including when it establishes that nothing happened.

// questions

Your questions, answered.

Ordinary recovery aims to return your files. Forensic recovery has to prove nothing was altered — so the source is read behind a write blocker, hashed to demonstrate the copy is identical, and every step logged so an independent party could repeat it and reach the same result.

Hardware that sits between the drive and the workstation and physically refuses write commands. It matters because simply connecting a drive normally can mount it, update access times and write files — any of which undermines the evidence before analysis has started.

Often. USB connection records, link files, jump lists, shellbag entries and file system timestamps together show which devices were attached, when, and what was opened around that time. What can be established varies by system and by how much has happened since.

The UK guidance for handling digital evidence: no action should change the data; where change is unavoidable the person must be competent to explain it; and an audit trail must exist such that an independent third party could repeat the process and reach the same conclusion.

From £800 plus VAT, quoted after a scoping discussion. Forensic work is not offered on a no-fix-no-fee basis and carries a 50% deposit, because the analysis has value whatever it concludes — including establishing that nothing improper occurred.