ServingNew York, New Jersey, and Connecticut
24/7 incident response1-800-868-8189Contact GDF

Workstations / servers / media

Computer and drive evidence, preserved at the source

Forensic acquisition is planned to minimize changes to the source while timeline, file, usage, and deletion analysis addresses the questions that brought the device into scope.

Chain-of-custody workflow from source identification through preservation, examination, and reporting
Drive work begins at the source and ends with a documented technical record.

A laptop can contain years of activity, but volume is not relevance. GDF scopes the acquisition around the operating system, storage design, encryption, user profiles, business applications, and the disputed period. Examiners use write protection and validated working copies where the source and acquisition method permit, and document any unavoidable change during live or logical collection.

Acquisition built around the storage system

Work may involve Windows, macOS, Linux, virtual machines, RAID arrays, network shares, external drives, or removable media. Examiners document device identifiers, connection methods, write protection, tool versions, errors, and cryptographic hashes. Full physical imaging, logical collection, targeted collection, or a combination may be selected based on proportionality and the evidence source.

Encryption, solid-state drive behavior, cloud-synchronized folders, snapshots, and enterprise endpoint controls can materially change what is recoverable. Those conditions are recorded rather than hidden behind a generic statement that a drive was copied.

Activity reconstructed from independent artifacts

File dates alone rarely settle a dispute. A sound chronology may draw from file-system journals, link files, recent-item records, application logs, browser data, USB history, cloud sync metadata, backups, registry records, and operating-system databases. Agreement among independent artifacts strengthens an inference; conflicts and gaps are reported.

  • User activity and document-access timelines
  • Copying to USB devices or synchronized repositories
  • Deletion, wiping, installation, and anti-forensic activity
  • Recovery assessment for damaged or partially readable media
  • Comparison of native files, exports, and produced documents

Results suitable for review and testimony

Deliverables can include a concise findings table, an artifact appendix, a full expert report, or a preserved image for later work. Counsel can see which facts come directly from the source, which are inferred, and which questions remain open. That separation supports efficient review and defensible testimony.

Plan a computer or drive examination

Tell us what is disputed, which devices or systems may hold the answer, and the next deadline. Counsel retains all legal decisions.

Contact GDF