Independent digital forensics.

Digital forensic acquisition, examination, and expert testimony for counsel, insurers, and corporate investigators.

Discuss a matter See services

Digital forensics

Everything from the first image to the witness stand.

Most engagements begin with preservation and stop wherever the question is answered. Each piece of work is documented so the next examiner, or an opposing one, can pick it up.

What we examine

The devices and accounts we acquire and examine.

Computers

Laptops and desktops. File activity, USB history, web and email, deleted files.

Servers and virtual machines

On-premises or hosted. Logins, shares, databases, and what was reached.

Phones and tablets

Messages, locations, photos, app data, and what was deleted.

Removable media

USB drives, external disks, memory cards. What was copied, and when.

Cloud and email accounts

Mailboxes, audit logs, sharing, and forwarding rules.

Network devices and logs

Firewalls, VPNs, Wi-Fi. Who connected, from where, and what moved.

Backups and archives

Data that survived after it was deleted from the live system.

Vehicles, wearables, and cameras

Infotainment, watches, video recorders. Where someone was, and when.

Three worked examples

What a single acquisition can tell us.

One acquisition, run on a single handset. Each line of output is something the owner may not know is still there.

$ sgc acquire --dev iphone --full [09:41:07] connect serial ····8F2Q [09:41:09] hash sha256 3f1a9c02… [09:41:31] parse sms.db 4,112 [09:41:38] recover IMG_4471.HEIC del [09:41:44] parse safari.db 2,310 [09:41:52] carve unalloc 1.2 GB [09:42:03] location 38.897,-77.036 [09:42:11] wifi Marriott_Guest [09:42:19] parse photos.db 9,807 [09:42:26] usb SanDisk 64GB [09:42:33] app Signal 1,204 msg [09:42:40] keychain 14 credentials [09:42:48] done SGC-2026-0117

Calls and messages

SMS, iMessage, and call logs, including entries the owner deleted.

Web history

Sites visited, searches, and downloads, including cleared history.

Networks joined

Wi-Fi networks and the times the device was on them.

App data

Messaging apps, including those built to leave nothing behind.

Deleted photos and files

Recovered from unallocated space with their original timestamps.

Location history

Where the device was, and when, from system and app records.

Removable media

Every USB drive connected, and what was copied to it.

$ sgc acquire --dev iphone --full [09:41:07] connect serial ····8F2Q [09:41:09] hash sha256 3f1a9c02… [09:41:31] parse sms.db 4,112 [09:41:38] recover IMG_4471.HEIC del [09:41:44] parse safari.db 2,310 [09:41:52] carve unalloc 1.2 GB [09:42:03] location 38.897,-77.036 [09:42:11] wifi Marriott_Guest [09:42:19] parse photos.db 9,807 [09:42:26] usb SanDisk 64GB [09:42:33] app Signal 1,204 msg [09:42:40] keychain 14 credentials [09:42:48] done SGC-2026-0117
  • Calls and messagesSMS, iMessage, and call logs, including entries the owner deleted.
  • Web historySites visited, searches, and downloads, including cleared history.
  • Networks joinedWi-Fi networks and the times the device was on them.
  • App dataMessaging apps, including those built to leave nothing behind.
  • Deleted photos and filesRecovered from unallocated space with their original timestamps.
  • Location historyWhere the device was, and when, from system and app records.
  • Removable mediaEvery USB drive connected, and what was copied to it.

One acquisition of a company laptop, imaged through a write blocker. Each line is something the user may not know is still there.

$ sgc acquire --dev latitude-5540 --full [14:02:11] connect write-blocked serial ····T8U [14:02:14] hash sha256 9b4e17d0… [14:03:40] parse $MFT 412,880 entries [14:03:52] parse usbstor.reg 6 devices [14:04:03] parse shellbags 1,204 folders [14:04:18] parse edge.db 28,410 rows [14:04:31] carve unalloc 118 GB [14:04:59] recover Q3_forecast.xlsx del 03/12 [14:05:12] parse outlook.ost 61,207 items [14:05:30] parse lnk 3,318 files [14:05:44] detect VeraCrypt hidden volume [14:05:58] parse evtx logon 1,940 events [14:06:10] done SGC-2026-0118

Files created, opened, and edited

Every file on the disk, with when it was made, changed, and last used.

Web history and downloads

Sites visited and files downloaded, including cleared history.

Email

Cached mailboxes, including messages deleted from the server.

Logins and sessions

Who signed in, when, from where, and for how long.

USB devices connected

Every drive plugged in, when, and what was copied to it.

Deleted files

Recovered from unallocated space with their original timestamps.

Encrypted and hidden volumes

Containers and tools built to keep an examiner out.

$ sgc acquire --dev latitude-5540 --full [14:02:11] connect write-blocked serial ····T8U [14:02:14] hash sha256 9b4e17d0… [14:03:40] parse $MFT 412,880 entries [14:03:52] parse usbstor.reg 6 devices [14:04:03] parse shellbags 1,204 folders [14:04:18] parse edge.db 28,410 rows [14:04:31] carve unalloc 118 GB [14:04:59] recover Q3_forecast.xlsx del 03/12 [14:05:12] parse outlook.ost 61,207 items [14:05:30] parse lnk 3,318 files [14:05:44] detect VeraCrypt hidden volume [14:05:58] parse evtx logon 1,940 events [14:06:10] done SGC-2026-0118
  • Files created, opened, and editedEvery file on the disk, with when it was made, changed, and last used.
  • Web history and downloadsSites visited and files downloaded, including cleared history.
  • EmailCached mailboxes, including messages deleted from the server.
  • Logins and sessionsWho signed in, when, from where, and for how long.
  • USB devices connectedEvery drive plugged in, when, and what was copied to it.
  • Deleted filesRecovered from unallocated space with their original timestamps.
  • Encrypted and hidden volumesContainers and tools built to keep an examiner out.

One Microsoft 365 or Google Workspace account, exported through the platform's own audit tools. Each line is something the user may not know is kept.

tenant.onmicrosoft.com · app-only access $ sgc acquire --tenant contoso --user jdoe --m365 [10:15:02] connect Graph API audit consent [10:15:05] export mailbox 84,120 items [10:15:40] export onedrive 12,308 files [10:16:02] parse sign-ins 90 days [10:16:20] parse sharing links 212 external [10:16:33] parse inbox rules 7 active [10:16:41] export teams chats 9,904 msgs [10:16:55] parse mfa events 41 [10:17:03] detect bulk download 2,140 files [10:17:12] parse recoverable 3,006 deleted [10:17:20] done SGC-2026-0119

Mailbox

Every message, attachment, and calendar item, including purged folders.

Files shared outside

Documents shared to personal accounts or public links, and when.

Bulk downloads

Unusual volumes pulled from OneDrive or SharePoint before a departure.

Deleted items

Mail and files recoverable from retention after the user removed them.

Files and version history

Every document, with each version and who edited it.

Sign-ins and locations

Where and when the account was used, and from which devices.

Forwarding rules

Inbox rules that quietly copy mail to another address.

tenant.onmicrosoft.com · app-only access $ sgc acquire --tenant contoso --user jdoe --m365 [10:15:02] connect Graph API audit consent [10:15:05] export mailbox 84,120 items [10:15:40] export onedrive 12,308 files [10:16:02] parse sign-ins 90 days [10:16:20] parse sharing links 212 external [10:16:33] parse inbox rules 7 active [10:16:41] export teams chats 9,904 msgs [10:16:55] parse mfa events 41 [10:17:03] detect bulk download 2,140 files [10:17:12] parse recoverable 3,006 deleted [10:17:20] done SGC-2026-0119
  • MailboxEvery message, attachment, and calendar item, including purged folders.
  • Files shared outsideDocuments shared to personal accounts or public links, and when.
  • Bulk downloadsUnusual volumes pulled from OneDrive or SharePoint before a departure.
  • Deleted itemsMail and files recoverable from retention after the user removed them.
  • Files and version historyEvery document, with each version and who edited it.
  • Sign-ins and locationsWhere and when the account was used, and from which devices.
  • Forwarding rulesInbox rules that quietly copy mail to another address.

Services

01

Acquisition and preservation

  • Forensic acquisition and imaging of computers, servers, and external media
  • Mobile device acquisition
  • Cloud and email acquisition, including Microsoft 365 and Google Workspace
  • Remote and targeted collection
  • Evidence preservation and chain of custody
  • Litigation hold support
  • Evidence storage and retention

02

Examination and analysis

  • Forensic examination and analysis
  • Timeline reconstruction
  • Deleted file recovery
  • Removable media and USB device history
  • Web activity and download analysis
  • Email and communications analysis
  • Encryption and anti-forensics detection
  • Malware artefact analysis

03

Investigation types

  • Insider threat investigations
  • Data exfiltration and intellectual property theft
  • Employee misconduct and HR investigation support
  • Departing employee review
  • Fraud investigation support
  • Incident response and compromise assessment

04

Deliverables and testimony

  • Written findings reports
  • Expert reports
  • Affidavits and declarations
  • Deposition and trial testimony
  • Opposing expert report review
  • Forensic protocol development and neutral examiner services

Business intelligence

An inventory of the business, built from its own records.

Most companies cannot list every system, subscription, vendor, account, and person with access. We reconstruct that list from the money and the data rather than from interviews, whether the occasion is a change of control or an internal audit.

Vendors and subscriptions

Each recurring charge resolved to the vendor behind it, with annual cost.

Bank and card accounts

Every account, card, and processor the company pays from or is paid into.

Payroll and contractors

Everyone the company pays, and payments that outlived a departure.

Customers and products

Who pays the company, for what, and how much, from inbound payments.

Cloud tenants and apps

Every SaaS tenant and integration, and who runs it.

Domains, DNS, and certificates

What the company owns online, and who can renew it.

Files and shares

What sits on servers and shares, and who owns it.

Devices

Laptops and phones issued, and the ones never returned.

People and access

Who has accounts, who has admin, and who should not.

Network telemetry

Firewall, VPN, and Wi-Fi logs: who connected, and what moved.

  • Bank and card accountsEvery account, card, and processor the company pays from or is paid into.
  • Vendors and subscriptionsEach recurring charge resolved to the vendor behind it, with annual cost.
  • Customers and productsWho pays the company, for what, and how much, from inbound payments.
  • Payroll and contractorsEveryone the company pays, and payments that outlived a departure.
  • Cloud tenants and appsEvery SaaS tenant and integration, and who runs it.
  • Domains, DNS, and certificatesWhat the company owns online, and who can renew it.
  • People and accessWho has accounts, who has admin, and who should not.
  • DevicesLaptops and phones issued, and the ones never returned.
  • Files and sharesWhat sits on servers and shares, and who owns it.
  • Network telemetryFirewall, VPN, and Wi-Fi logs: who connected, and what moved.

The business, enumerated. Every flow of money and data points to something the company runs on, pays for, or is paid for.

What it is

A forensic inventory of a company. Instead of asking people what the business runs on, we read the company's own records: the money it moved, the systems it logged into, the traffic on its network, the files on its machines, and the history in its browsers. Reconciled, they make one picture. The result is a complete, evidenced list of the systems, subscriptions, vendors, customers, and accounts the company depends on, and of the people who control each one.

The list nobody had is only half the value. The other half is the gap between it and what everyone believed: the subscriptions still billing with no user, the administrator accounts held by people who left, the domains about to lapse, the contractor still being paid.

It is used at acquisitions and mergers, in receiverships and estates, after a founder or executive leaves, for internal audit and compliance reviews, and when preparing a company for sale.

How it works

1  Gather the records

Bank, card, and payroll statements and the accounting export. The identity directory and every OAuth grant. Domain and DNS registrations. Mailboxes. Firewall, VPN, and network logs. Browser histories, and the files on laptops, servers, and shared drives. Nothing is taken on anyone's say-so.

2  Cross-reference every source

Each source is a partial view; together they corroborate. A recurring charge names a vendor. Browser history shows who used it and how often. Network logs show the traffic. A shared drive holds the contract. Where the sources agree, an item is confirmed. Where they disagree or a trail runs cold, something is orphaned, unknown, or unaccounted for.

3  Hand over the inventory

Registers of systems, vendors, customers, and people. A map of how money and data move between them. A list of everything with no owner, no contract, or no business reason. For a change of control, a plan for transferring access. For an audit, a plan for tightening it.

A typical engagement

A buyer closes on a forty-person software company and inherits a spreadsheet titled "all our tools" with thirty-eight lines on it. The inventory finds two hundred and twelve applications in single sign-on, a hundred and thirty-seven recurring vendors, fourteen subscriptions still billing with no user, nine administrator accounts held by people who no longer work there, and two contractors still being paid. The buyer has a list they can act on before the first invoice arrives.

Drone forensics

What an aircraft, its controller, and its pilot's phone recorded.

A drone keeps a second-by-second record of where it went, what it looked at, and who was flying it. That record is spread across the aircraft, its removable media, the controller, the pilot's phone, and the manufacturer's cloud. We recover all of it, including from aircraft that have crashed or been in water.

H

Flight path

Every logged position, with the passes still to fly.

Pilot position

From the controller's own GPS, not the aircraft's.

Home point and return line

Where it took off, and the path it would take back.

Aircraft, at this second

Position, altitude, heading, and attitude from the log.

Photographs

Each frame placed where and when it was taken.

Camera view and ground footprint

What the lens covered, and what it could not have seen.

H
  • Flight pathEvery logged position, with the passes still to fly.
  • Home point and return lineWhere it took off, and the path it would take back.
  • Pilot positionFrom the controller's own GPS, not the aircraft's.
  • Aircraft, at this secondPosition, altitude, heading, and attitude from the log.
  • Camera view and ground footprintWhat the lens covered, and what it could not have seen.
  • PhotographsEach frame placed where and when it was taken.

The flight, reconstructed. Every log entry becomes a point in space and time, so the flight can be replayed, measured, and set beside the photographs it produced.

What it is

A reconstruction of a flight from the records the aircraft, its controller, and the pilot's phone kept. A drone logs its position, altitude, heading, battery, and camera angle several times a second, and every photograph it takes carries the place and time it was made. We recover those records, verify them against one another, and rebuild the flight so it can be replayed, measured, and set beside the images it produced.

Because the record comes from the aircraft rather than from anyone's account of the flight, it settles the questions that usually get argued: where the aircraft actually went, how high, what the camera could see, and who was holding the controller.

It is used for restricted airspace and site incursions, surveillance complaints, contraband deliveries to secure facilities, crashes and property damage claims, seized aircraft with an unknown operator, and insurance and FAA matters.

How it works

1  Recover the records

Flight logs from the aircraft's internal storage, photos and video from its memory card, the controller's own position track, the pilot's phone app and its synced logs, and the manufacturer's cloud account. Damaged and water-immersed aircraft included.

2  Rebuild the flight

Each log entry becomes a point in space and time. The tracks from the aircraft, the controller, and the phone are checked against each other and against the photographs, so a gap or an edit in one source shows up in the others.

3  Answer the question

Where it went, how high, what the camera pointed at, who owned and flew it, whether a geofence was unlocked, and what caused a crash: mechanical, battery, signal loss, or pilot input. Delivered as a map and timeline, with report and testimony as for any other examination.

A typical engagement

A facility reports a drone over its perimeter at night. Two weeks later a damaged aircraft is found in a drainage channel nearby. From its internal log, the flight is rebuilt: take-off from a car park half a mile away, three passes along the fence line at forty metres with the camera pointed down, and a return that ended in a tree. The phone paired to the aircraft names the operator.

How we work

Preserve first. Examine only verified copies. Report what the evidence supports.

Every matter opens with a short scoping call to identify the custodians, devices, and accounts involved, and the question the evidence needs to answer. A conflict check runs before any detail beyond the parties' names is discussed. The work then follows the four phases set out in NIST SP 800-86 and ISO/IEC 27037.

1  Collection

Sources are identified, then imaged or collected forensically, hashed on acquisition, and entered into the chain of custody. Originals go into sealed storage. Everything that follows runs on verified copies.

2  Examination

Relevant data is extracted from the copies: deleted files recovered, containers decrypted, unallocated space carved, and system, mail, and browser records parsed. Each step is logged with the tool and version used.

3  Analysis

The extracted artefacts are interpreted against the question in the matter: what happened, in what order, and by whom. Every conclusion names the artefacts that support it, so another examiner can reproduce the reasoning.

4  Reporting

Findings are written in plain language with the technical detail in appendices. If the matter proceeds, the examiner who did the work signs the declaration and gives the testimony.

Testimony

Written to be reproduced. Defended in person.

Every report states what was examined, how, and with which tools, in enough detail that an opposing examiner can repeat the steps. The same person who did the work signs the affidavit and sits for deposition and trial.

  • Reports structured for a reader who is not technical, with method and artefact detail in appendices
  • Review of opposing expert reports for method, omissions, and unsupported conclusions
  • Neutral examiner and protocol work where both sides need a process they can agree to
ItemSGC-2026-0117-003
SourceLaptop, serial [SAMPLE]
MethodPhysical image, write-blocked
Acquired2026-03-14 09:12:41 UTC
SHA-2563f1a9c02 … 4d7e07b1 verified
CustodySealed, logged, in storage
Examiner[EXAMINER NAME]

Chain-of-custody entry as it appears in a report appendix. Values shown are illustrative.

Contact

Discuss a matter.

Initial calls are confidential and without obligation. Tell us what the matter involves and when evidence may be at risk, and we will tell you what to protect first.

Call  Email 

Mailing address

2 Massachusetts Ave NE #1058
Washington, DC 20002

Evidence intake

Devices and media can be collected on site or sent by tracked courier. Do not power on, charge, or wipe a device before speaking with us.