Selected case experience

Selected Digital Forensic Case Experience

Examples drawn from completed work for law firms, organisations, people representing themselves and specialist providers. Each section describes the questions encountered, sources considered and limits that matter when reporting. A new matter may require a different scope because its evidence and procedural setting will differ.

Client categories shown · Evidence-led scope · Findings and limitations reported together

A varied independent practice

Different clients bring different evidence problems

Instructions have come directly from solicitors and legal teams, commercial organisations, public-sector bodies, private individuals and people conducting their own cases. Compute Forensics has also provided defined collection, examination and reporting work to forensic, expert and eDiscovery firms when they needed additional senior capacity.

The work ranges from an early view on whether a technical issue is worth pursuing to preservation, detailed examination, expert reporting, conferences and hearing support. The appropriate route depends on the question and on what evidence still exists, not simply on the client category.

Law firms and legal teams

Independent report review, computer and mobile examination, electronic-file provenance and expert evidence for criminal, civil, commercial, employment and insurance matters.

Organisations and private clients

Preservation and investigation involving computers, storage, email, cloud records, messages, workplace activity, data loss and post-incident reconstruction.

Forensic and eDiscovery providers

Overflow casework, targeted collection, imaging, processing support, documented hand-off and independent technical reporting for a defined work package.

Email, document and media provenance

Several copies, several dates, one provenance question

Client categories: Individual representing themselves, private client or solicitor

Provenance instructions have involved disputed emails, PDFs, office documents and video supplied in more than one form. Printed dates, file-system timestamps and document properties can refer to different events, so the examination usually starts with the earliest native copy and a record of how each version was obtained.

The examination preserves and hashes the supplied files before comparing structure, embedded material and technical metadata. Depending on the format, this may include email routing and MIME data, PDF objects and incremental updates, document properties, container and codec information, or signs of export and re-encoding. Related messages, attachments and transfer notes can help place those observations in context.

The chronology records what the files show and which points, such as authorship, transmission or alteration, remain interpretations.

Workplace investigation

Preserving a computer before routine IT work changed the record

Client categories: Corporate organisation, in-house legal team or HR

Workplace instructions have involved concerns about confidential files around an employee departure, a dispute or unusual access. Reissuing a laptop, resetting an account or running ordinary support tools can alter the very artefacts needed to understand what happened, so preservation is often the first priority.

Once authority and scope are clear, the available computer, forensic image or defined account records can be examined against the relevant period. File-system activity may be compared with removable-media history, application records, email or cloud synchronisation and the dates supplied by the organisation. The analysis also records gaps, shared-device use and activity that may have more than one explanation.

A staged instruction allows the organisation and its advisers to decide whether a broader examination is proportionate after the initial preservation and triage.

eDiscovery collection

From custodian list to a reviewable collection

Client categories: Law firm, corporate legal team or eDiscovery provider

eDisclosure work has involved computers, mailboxes, cloud repositories, shared storage and removable media held by several custodians. The task is to collect only what has been authorised, preserve useful metadata and give the review team a clear record of omissions or format changes.

The work begins with the legal team defining custodians, systems, date ranges and subject matter. Technical scoping then identifies which sources can be imaged, exported or collected remotely, how access will be provided and what the receiving platform needs. Where included, processing can cover culling, deduplication, search-term testing and preparation for review, with responsibilities stated before work begins.

Unavailable accounts, retention limits, licensing, encryption and export restrictions are logged as exceptions.

Cyber-breach investigation

Rebuilding the timeline after containment

Client categories: Corporate organisation, insurer or external legal adviser

Across his wider career, Alistair has worked on more than 70 cyber-breach investigations as a managing consultant or technical lead, with regional responsibility across Europe, Africa and the Middle East. That work has included ransomware and extortion, identity and cloud compromise, business-email compromise, suspected insider activity, possible exfiltration and destructive incidents.

After immediate containment, the available evidence rarely sits in one place. Preserved endpoints and memory may need to be considered alongside identity and cloud audit records, endpoint telemetry, mailbox data, firewall, proxy, DNS or VPN logs and the incident notes created during response. Timestamps are aligned before suspected access, persistence, lateral movement and data-transfer paths are tested against the different sources.

The resulting chronology separates recorded events from technical interpretation and makes clear what remains unresolved.

Remote and attended collection

Choosing the collection route from the source state

Client categories: Specialist forensic provider, eDiscovery firm, law firm or corporate client

Collection work has included sources located far from the receiving laboratory or review team. The source state determines the method. A suitable live computer may be collected through a case-specific encrypted agent, while a switched-off system may be started into a controlled environment from prepared USB or optical media. Some devices still require attendance or another specialist route.

Before collection, the instruction records authority, the exact source, the operator at the device, what is to be acquired and how the result will be transferred. The person at the device follows documented steps; forensic decisions remain with the examiner. Where the method allows, the collection is verified, encrypted and handed over with relevant hashes and a record of any exceptions.

This gives the receiving examiner or provider a clear account of what was requested, what the method could access and what was actually delivered.

Case-specific advice

Every new instruction starts with its own evidence

These examples show the types of questions and material that have arisen in practice. They are not templates for the answer in a new matter. Source condition, access, retention, procedural setting and the precise question can all change what work is possible and worthwhile.

Start with the evidence question

Discuss the question and the evidence available

Send the party names, the question, the types of source available and the deadline. Do not send evidence or confidential case details through the public form.

Discuss a similar evidence question