A resignation to a rival, a handed-back laptop, one question to answer: had company data gone with them? A forensically sound investigation in OSForensics.
When a salesperson quit a Oxford company to join a direct rival, the firm suspected the worst: that the client database and current price lists had been copied before the laptop came back. They couldn’t prove it, and they needed to — to a standard their solicitors could rely on. The question was narrow and specific: had data left the business, and by what means? Answering it, and evidencing the answer, was what they instructed us to do.
The soundness of the whole exercise depended on how the evidence was handled, so the laptop was never examined directly. Our first act was to make a forensic duplicate of the returned Windows 10 machine: a write-blocked, hash-checked .E01 acquisition — the PC3000 doing the job on any disk that isn’t fully stable. That done, the hardware was sealed in a bag and stored, and from there we only ever looked at a read-only mount of the duplicate. OSForensics ran the analysis with its audit log on, making every step we took reproducible and tamper-evident.
Everything hinged on the file-activity record, and it was unambiguous: on one evening — forty-eight hours before the resignation — the client database and a batch of price-list spreadsheets had been written out in quick succession. What device received them showed up when we lined that evening against the machine’s USB history, which OSForensics rebuilds from Windows event logs alongside the USBSTOR entries in the registry: a SanDisk stick, logged by serial number, connected just after the files were exported and unplugged a short time later. Email and web traffic filled in the motive and the second channel — the user’s OST mail store, once indexed, held two messages to a private address with a price list attached, and the browsing record from the same minutes captured a webmail login and a file sent up to personal cloud storage. A number of the exports had been deleted afterwards; those we recovered by carving them from the image.
OSForensics produced the deliverable itself: a hash-verified report that drew every thread into one place — the exported files and when they were written, the SanDisk device and its timestamps, the two emails, the cloud upload, and the deletions we’d recovered — each anchored to the audit trail. That report went to the firm’s legal team to act on as they saw fit. Start to finish, five working days. Workplace investigations we undertake only for the owner of the equipment, and only on written instruction.
OSForensics · PC3000 — a write-blocked, hash-verified image examined read-only; USB history, file timeline, mailbox and recovered deletions drawn into an audit-trailed report. For the equipment’s owner only, on written instruction.
Send us your device for a free diagnostic, and tell us a little about what happened — an engineer will review it and confirm your exact quote in writing before any work begins.
Getting your data back begins with getting the device to us. Pack it up safely, pop your contact details inside, and send it over — once we’ve run the free diagnostic, we’ll confirm your exact price in writing before any work starts.
Posting it? A tracked, insured service is what we’d recommend. Rather drop it in? You’re welcome Monday to Friday, 9am to 5:30pm — just package the device up as above first.
Want a bit more detail first? Fill in the form with more about your issue and an engineer will review it and send you a custom quote.
We’ll be in touch shortly. For anything urgent, call 01865 593000.
Forensic recovery establishes what happened on a device and preserves the evidence so it stands up later. Media is imaged behind a write blocker, hashed to prove the copy is identical, and every step logged so the chain of custody holds — typically following ACPO principles for digital evidence.
Often, yes. USB connection records, link files, jump lists, registry artefacts and file system timestamps together show what was attached and what was opened or copied, and when. What can be proven varies by system and by how much has happened since.
Forensic investigation starts from £800 plus VAT, quoted after a scoping discussion. Forensic work is not offered on a no-fix-no-fee basis and carries a 50% deposit, because the analysis has value whatever it concludes.
Start with an instant online quote, or call and talk it through with us first. You'll have a clear, fixed price before any work begins.