Digital forensic acquisition, examination, and expert testimony for counsel, insurers, and corporate investigators.
Digital forensics
Most engagements begin with preservation and stop wherever the question is answered. Each piece of work is documented so the next examiner, or an opposing one, can pick it up.
What we examine
Computers
Laptops and desktops. File activity, USB history, web and email, deleted files.
Servers and virtual machines
On-premises or hosted. Logins, shares, databases, and what was reached.
Phones and tablets
Messages, locations, photos, app data, and what was deleted.
Removable media
USB drives, external disks, memory cards. What was copied, and when.
Cloud and email accounts
Mailboxes, audit logs, sharing, and forwarding rules.
Network devices and logs
Firewalls, VPNs, Wi-Fi. Who connected, from where, and what moved.
Backups and archives
Data that survived after it was deleted from the live system.
Vehicles, wearables, and cameras
Infotainment, watches, video recorders. Where someone was, and when.
Three worked examples
One acquisition, run on a single handset. Each line of output is something the owner may not know is still there.
Calls and messages
SMS, iMessage, and call logs, including entries the owner deleted.
Web history
Sites visited, searches, and downloads, including cleared history.
Networks joined
Wi-Fi networks and the times the device was on them.
App data
Messaging apps, including those built to leave nothing behind.
Deleted photos and files
Recovered from unallocated space with their original timestamps.
Location history
Where the device was, and when, from system and app records.
Removable media
Every USB drive connected, and what was copied to it.
One acquisition of a company laptop, imaged through a write blocker. Each line is something the user may not know is still there.
Files created, opened, and edited
Every file on the disk, with when it was made, changed, and last used.
Web history and downloads
Sites visited and files downloaded, including cleared history.
Cached mailboxes, including messages deleted from the server.
Logins and sessions
Who signed in, when, from where, and for how long.
USB devices connected
Every drive plugged in, when, and what was copied to it.
Deleted files
Recovered from unallocated space with their original timestamps.
Encrypted and hidden volumes
Containers and tools built to keep an examiner out.
One Microsoft 365 or Google Workspace account, exported through the platform's own audit tools. Each line is something the user may not know is kept.
Mailbox
Every message, attachment, and calendar item, including purged folders.
Files shared outside
Documents shared to personal accounts or public links, and when.
Bulk downloads
Unusual volumes pulled from OneDrive or SharePoint before a departure.
Deleted items
Mail and files recoverable from retention after the user removed them.
Files and version history
Every document, with each version and who edited it.
Sign-ins and locations
Where and when the account was used, and from which devices.
Forwarding rules
Inbox rules that quietly copy mail to another address.
Services
01
02
03
04
Business intelligence
Most companies cannot list every system, subscription, vendor, account, and person with access. We reconstruct that list from the money and the data rather than from interviews, whether the occasion is a change of control or an internal audit.
Vendors and subscriptions
Each recurring charge resolved to the vendor behind it, with annual cost.
Bank and card accounts
Every account, card, and processor the company pays from or is paid into.
Payroll and contractors
Everyone the company pays, and payments that outlived a departure.
Customers and products
Who pays the company, for what, and how much, from inbound payments.
Cloud tenants and apps
Every SaaS tenant and integration, and who runs it.
Domains, DNS, and certificates
What the company owns online, and who can renew it.
Files and shares
What sits on servers and shares, and who owns it.
Devices
Laptops and phones issued, and the ones never returned.
People and access
Who has accounts, who has admin, and who should not.
Network telemetry
Firewall, VPN, and Wi-Fi logs: who connected, and what moved.
The business, enumerated. Every flow of money and data points to something the company runs on, pays for, or is paid for.
A forensic inventory of a company. Instead of asking people what the business runs on, we read the company's own records: the money it moved, the systems it logged into, the traffic on its network, the files on its machines, and the history in its browsers. Reconciled, they make one picture. The result is a complete, evidenced list of the systems, subscriptions, vendors, customers, and accounts the company depends on, and of the people who control each one.
The list nobody had is only half the value. The other half is the gap between it and what everyone believed: the subscriptions still billing with no user, the administrator accounts held by people who left, the domains about to lapse, the contractor still being paid.
It is used at acquisitions and mergers, in receiverships and estates, after a founder or executive leaves, for internal audit and compliance reviews, and when preparing a company for sale.
1 Gather the records
Bank, card, and payroll statements and the accounting export. The identity directory and every OAuth grant. Domain and DNS registrations. Mailboxes. Firewall, VPN, and network logs. Browser histories, and the files on laptops, servers, and shared drives. Nothing is taken on anyone's say-so.
2 Cross-reference every source
Each source is a partial view; together they corroborate. A recurring charge names a vendor. Browser history shows who used it and how often. Network logs show the traffic. A shared drive holds the contract. Where the sources agree, an item is confirmed. Where they disagree or a trail runs cold, something is orphaned, unknown, or unaccounted for.
3 Hand over the inventory
Registers of systems, vendors, customers, and people. A map of how money and data move between them. A list of everything with no owner, no contract, or no business reason. For a change of control, a plan for transferring access. For an audit, a plan for tightening it.
A typical engagement
A buyer closes on a forty-person software company and inherits a spreadsheet titled "all our tools" with thirty-eight lines on it. The inventory finds two hundred and twelve applications in single sign-on, a hundred and thirty-seven recurring vendors, fourteen subscriptions still billing with no user, nine administrator accounts held by people who no longer work there, and two contractors still being paid. The buyer has a list they can act on before the first invoice arrives.
Drone forensics
A drone keeps a second-by-second record of where it went, what it looked at, and who was flying it. That record is spread across the aircraft, its removable media, the controller, the pilot's phone, and the manufacturer's cloud. We recover all of it, including from aircraft that have crashed or been in water.
Flight path
Every logged position, with the passes still to fly.
Pilot position
From the controller's own GPS, not the aircraft's.
Home point and return line
Where it took off, and the path it would take back.
Aircraft, at this second
Position, altitude, heading, and attitude from the log.
Photographs
Each frame placed where and when it was taken.
Camera view and ground footprint
What the lens covered, and what it could not have seen.
The flight, reconstructed. Every log entry becomes a point in space and time, so the flight can be replayed, measured, and set beside the photographs it produced.
A reconstruction of a flight from the records the aircraft, its controller, and the pilot's phone kept. A drone logs its position, altitude, heading, battery, and camera angle several times a second, and every photograph it takes carries the place and time it was made. We recover those records, verify them against one another, and rebuild the flight so it can be replayed, measured, and set beside the images it produced.
Because the record comes from the aircraft rather than from anyone's account of the flight, it settles the questions that usually get argued: where the aircraft actually went, how high, what the camera could see, and who was holding the controller.
It is used for restricted airspace and site incursions, surveillance complaints, contraband deliveries to secure facilities, crashes and property damage claims, seized aircraft with an unknown operator, and insurance and FAA matters.
1 Recover the records
Flight logs from the aircraft's internal storage, photos and video from its memory card, the controller's own position track, the pilot's phone app and its synced logs, and the manufacturer's cloud account. Damaged and water-immersed aircraft included.
2 Rebuild the flight
Each log entry becomes a point in space and time. The tracks from the aircraft, the controller, and the phone are checked against each other and against the photographs, so a gap or an edit in one source shows up in the others.
3 Answer the question
Where it went, how high, what the camera pointed at, who owned and flew it, whether a geofence was unlocked, and what caused a crash: mechanical, battery, signal loss, or pilot input. Delivered as a map and timeline, with report and testimony as for any other examination.
A typical engagement
A facility reports a drone over its perimeter at night. Two weeks later a damaged aircraft is found in a drainage channel nearby. From its internal log, the flight is rebuilt: take-off from a car park half a mile away, three passes along the fence line at forty metres with the camera pointed down, and a return that ended in a tree. The phone paired to the aircraft names the operator.
How we work
Every matter opens with a short scoping call to identify the custodians, devices, and accounts involved, and the question the evidence needs to answer. A conflict check runs before any detail beyond the parties' names is discussed. The work then follows the four phases set out in NIST SP 800-86 and ISO/IEC 27037.
1 Collection
Sources are identified, then imaged or collected forensically, hashed on acquisition, and entered into the chain of custody. Originals go into sealed storage. Everything that follows runs on verified copies.
2 Examination
Relevant data is extracted from the copies: deleted files recovered, containers decrypted, unallocated space carved, and system, mail, and browser records parsed. Each step is logged with the tool and version used.
3 Analysis
The extracted artefacts are interpreted against the question in the matter: what happened, in what order, and by whom. Every conclusion names the artefacts that support it, so another examiner can reproduce the reasoning.
4 Reporting
Findings are written in plain language with the technical detail in appendices. If the matter proceeds, the examiner who did the work signs the declaration and gives the testimony.
Testimony
Every report states what was examined, how, and with which tools, in enough detail that an opposing examiner can repeat the steps. The same person who did the work signs the affidavit and sits for deposition and trial.
Chain-of-custody entry as it appears in a report appendix. Values shown are illustrative.
Contact
Initial calls are confidential and without obligation. Tell us what the matter involves and when evidence may be at risk, and we will tell you what to protect first.
Mailing address
2 Massachusetts Ave NE #1058
Washington, DC 20002
Evidence intake
Devices and media can be collected on site or sent by tracked courier. Do not power on, charge, or wipe a device before speaking with us.