Skip to content

Laptops · Desktops · Servers · Windows and macOS

Computer forensics

Someone says a folder was copied before they resigned. Someone else says it never happened. The laptop kept its own account of that week, and it did not consult either of them.

Most of what a computer records, nobody chose to record.

A user copies a client folder to a thumb drive and deletes the original. The file is gone. Still present are the registry entry naming the drive and its serial number, the timestamp of the moment it was attached, the shortcut Windows wrote when the folder was opened from that drive, the prefetch entry showing the program that did the copying, and the event log line recording the session it happened in. Five separate systems, none of which the user knows exist, each writing for its own reasons.

That is the substance of a computer examination. Not a single artifact answering the question, but a set of independent artifacts written by different parts of the operating system at different moments, compared against each other to see whether they agree.

One artifact is a hypothesis. Several that agree is a finding.

Scope

What gets examined

System and user artifacts

Registry hives, prefetch, Windows event logs, LNK files and jumplists, shellbags, recent items, and file system metadata. The record of what ran, what was opened, and in what order.

USB and removable device activity

Which external drives were connected to the machine, their make, model, and serial numbers, when each was first and last attached, and which user account was logged in at the time.

Cloud sync and upload activity

Personal Dropbox, Google Drive, OneDrive, and webmail activity on a company machine. Sync client logs, browser history, and local cache records showing what left the endpoint by that route.

File access and transfer history

What files a user opened, renamed, moved, printed, or archived, and when. Compressed archives assembled shortly before a departure are a pattern the file system records plainly.

Deleted file recovery

Recovery of deleted files and file system records where they survive, along with the residue that remains when the content itself does not. Absence of a file is itself documented rather than assumed.

Timeline reconstruction and attribution

Artifacts across the system placed on one timeline, then tied to a user account and a session. What happened, in what sequence, and which logged-in user the evidence supports.

Matters

Where this work is used

  • Trade secret and intellectual property theft. What was accessed, what was copied, where it went, and whether the timing lines up with the departure.
  • Non-compete and departing employee matters. Activity in the final weeks of employment, including transfers to personal accounts and removable media.
  • Employment disputes. Documents, communications, and file activity relevant to a termination, harassment claim, or performance dispute.
  • Internal fraud. Document creation and revision history, access to systems outside a role, and reconstruction of the sequence of events.
  • Policy violation. Use of unauthorized software or storage, circumvention of controls, and handling of data outside the terms an employee agreed to.

Method

How findings are produced and stated

  • Analysis runs on the image, never the original. The source drive is acquired write-blocked and set aside. Every examination step happens on a verified copy.
  • Artifacts are corroborated before they are reported. A single registry key is a lead. It becomes a finding when independent sources written by different subsystems agree with it.
  • Interpretation is separated from observation. The report distinguishes what the artifact says from what it reasonably implies, and marks which is which.
  • Method is documented well enough to repeat. Tool, version, and procedure are recorded so another examiner working from the same image reaches the same result.
  • Limits are stated. Where the evidence stops, the report says so rather than filling the gap with inference.

Before the laptop goes back in the pool

The most common way this evidence is lost is routine IT process. A departing employee's machine gets wiped and reissued in the ordinary course, weeks before anyone decides there is a matter. Nothing about that is bad faith, and it ends the examination before it starts. If a device might matter, take it out of the refresh cycle first and decide later.

Pricing

Imaging is priced apart from examination

Hard drive imaging is a flat $1,500 per drive, covering acquisition, hash verification, chain of custody documentation, and output formatted for review. Examination is billed hourly at $150 and only when the matter calls for it. You can take the collected output and search it yourself, or engage 4n6PI to perform the investigation. Where a matter needs one, a review platform is provided.

Details of acquisition method and rates are on the forensic collection page. A standing retainer puts rates and billing terms in place before a matter arrives, at no cost to establish.

Multi-device matters are quoted per engagement.

Start with the device, not the theory

The first conversation is free and takes about thirty minutes. Bring what you know and what you suspect, and we will tell you whether the machine is likely to answer it.