Computer & Media Examination
Computer and media examinations cover desktops, laptops, servers, external hard drives, USB flash drives, optical media, and a broad range of less common storage including SD cards, embedded controllers, and specialty devices.
Forensic imaging and verification is the foundation: we work from a verified copy of the evidence, leaving the original untouched. Examination addresses user-account activity, logon and logoff history, installed and executed applications, document and file activity, internet and browser artifacts, USB and external-device connections, anti-forensic indicators (file wiping, time-stamp manipulation, encryption containers), and recovery of deleted or partially overwritten content.
Where evidence is physically damaged, our affiliated data recovery operation provides clean-room recovery, including complex RAID, SSD, and chip-off recoveries of devices that other examiners cannot read.