Preserving Integrity of systems for analysis:
It is critical to preserve the data on suspect assets and not allow a system to be modified
any more than absolute necessary. Follow these steps to maintain a system and prepare it for
forensic analysis
1) Maintain the State:
If the system is on, leave it on, if it is off, leave it off. If a system is on; we will collect
volatile data. If a system if off; the act of turning it on will modify hundreds of files.
We collect data outside of the host system so no data is ever modified.
2) NO ACCESS
Do not allow any access to the computer or system. Any access will change timestamp data and
potentially overwrite any previously deleted or modified data.
3) Do not attempt to copy data
Copying the data in a "non-forensic" manner can destroy all possibility of using the data for
investigative purposes. We copy data on a bit by bit process that verifies all data is
forensically sound.
Follow these steps and contact us at the first opportunity and you will be taking the steps
you need to ensure we are able to help you.
Computer Forensics
If your data has been lost, modified, hidden, destroyed or disguised we can usually find and preserve
it. If it is still stored somehow on your computers or networks we will find it.
Nearly every civil or criminal case involves a computer, cell phone, MP3 player or network data of
some type, often the evidence contained on these resources is overlooked.
Our team of formally trained experts have the capabilities to recover, secure and analyze and present
this data. We are able to analyze all types of data ranging from deleted and hidden data to email files,
internet logs, encrypted data and more. We are able to support your litigation needs start to
finish, from initial incident response through expert witness support.
Our Digital Forensic Services Include:
-
Electronic Discovery
-
Forensic Imaging Services (in our lab or on site)
-
Password and Encryption Cracking
Media Analysis
-
File Recovery
-
Data Provenance (Timeline verification / reconstruction)
-
Email Analysis / Recovery
-
Internet Forensics - Tracing, Websites visited, etc.
-
Incident Response (Website / Network Hacking and Intrusions)
-
Data Culling - removal of excess data
-
Mobile phone and PDA Analysis
The services above represent the most common services we perform according to client needs.
Each situation is unique and as such we craft "bespoke" services for our
prospective clients. Our goal is to always provide the services that will help resolve each matter
in the best manner possible.