Selected case experience
Selected Digital Forensic Case Experience
Examples drawn from completed work for law firms, organisations, people representing themselves and specialist providers. Each section describes the questions encountered, sources considered and limits that matter when reporting. A new matter may require a different scope because its evidence and procedural setting will differ.
Client categories shown · Evidence-led scope · Findings and limitations reported together
A varied independent practice
Different clients bring different evidence problems
Instructions have come directly from solicitors and legal teams, commercial organisations, public-sector bodies, private individuals and people conducting their own cases. Compute Forensics has also provided defined collection, examination and reporting work to forensic, expert and eDiscovery firms when they needed additional senior capacity.
The work ranges from an early view on whether a technical issue is worth pursuing to preservation, detailed examination, expert reporting, conferences and hearing support. The appropriate route depends on the question and on what evidence still exists, not simply on the client category.
Law firms and legal teams
Independent report review, computer and mobile examination, electronic-file provenance and expert evidence for criminal, civil, commercial, employment and insurance matters.
Organisations and private clients
Preservation and investigation involving computers, storage, email, cloud records, messages, workplace activity, data loss and post-incident reconstruction.
Forensic and eDiscovery providers
Overflow casework, targeted collection, imaging, processing support, documented hand-off and independent technical reporting for a defined work package.
Browse the examples
Choose the question closest to your matter
Report and extraction review
A review that began with what the report actually cited
Client categories: Law firm or legal team
Legal teams have instructed Alistair after receiving a technical report, Streamlined Forensic Report, extraction or evidential schedule. The useful starting point is the statement that matters to the case and the source record said to support it.
The review follows the cited paths, record identifiers and timestamps back into the available extraction. It then checks surrounding entries, time-zone handling, totals and the way the application created or displayed the record. With mobile evidence, it may be important to distinguish a database entry from a report view, a screenshot or an assertion about who was holding the device.
This can confirm which conclusions are supported, show where context changes their significance and identify questions that cannot be answered without the missing acquisition records.
Email, document and media provenance
Several copies, several dates, one provenance question
Client categories: Individual representing themselves, private client or solicitor
Provenance instructions have involved disputed emails, PDFs, office documents and video supplied in more than one form. Printed dates, file-system timestamps and document properties can refer to different events, so the examination usually starts with the earliest native copy and a record of how each version was obtained.
The examination preserves and hashes the supplied files before comparing structure, embedded material and technical metadata. Depending on the format, this may include email routing and MIME data, PDF objects and incremental updates, document properties, container and codec information, or signs of export and re-encoding. Related messages, attachments and transfer notes can help place those observations in context.
The chronology records what the files show and which points, such as authorship, transmission or alteration, remain interpretations.
Workplace investigation
Preserving a computer before routine IT work changed the record
Client categories: Corporate organisation, in-house legal team or HR
Workplace instructions have involved concerns about confidential files around an employee departure, a dispute or unusual access. Reissuing a laptop, resetting an account or running ordinary support tools can alter the very artefacts needed to understand what happened, so preservation is often the first priority.
Once authority and scope are clear, the available computer, forensic image or defined account records can be examined against the relevant period. File-system activity may be compared with removable-media history, application records, email or cloud synchronisation and the dates supplied by the organisation. The analysis also records gaps, shared-device use and activity that may have more than one explanation.
A staged instruction allows the organisation and its advisers to decide whether a broader examination is proportionate after the initial preservation and triage.
eDiscovery collection
From custodian list to a reviewable collection
Client categories: Law firm, corporate legal team or eDiscovery provider
eDisclosure work has involved computers, mailboxes, cloud repositories, shared storage and removable media held by several custodians. The task is to collect only what has been authorised, preserve useful metadata and give the review team a clear record of omissions or format changes.
The work begins with the legal team defining custodians, systems, date ranges and subject matter. Technical scoping then identifies which sources can be imaged, exported or collected remotely, how access will be provided and what the receiving platform needs. Where included, processing can cover culling, deduplication, search-term testing and preparation for review, with responsibilities stated before work begins.
Unavailable accounts, retention limits, licensing, encryption and export restrictions are logged as exceptions.
Cyber-breach investigation
Rebuilding the timeline after containment
Client categories: Corporate organisation, insurer or external legal adviser
Across his wider career, Alistair has worked on more than 70 cyber-breach investigations as a managing consultant or technical lead, with regional responsibility across Europe, Africa and the Middle East. That work has included ransomware and extortion, identity and cloud compromise, business-email compromise, suspected insider activity, possible exfiltration and destructive incidents.
After immediate containment, the available evidence rarely sits in one place. Preserved endpoints and memory may need to be considered alongside identity and cloud audit records, endpoint telemetry, mailbox data, firewall, proxy, DNS or VPN logs and the incident notes created during response. Timestamps are aligned before suspected access, persistence, lateral movement and data-transfer paths are tested against the different sources.
The resulting chronology separates recorded events from technical interpretation and makes clear what remains unresolved.
Remote and attended collection
Choosing the collection route from the source state
Client categories: Specialist forensic provider, eDiscovery firm, law firm or corporate client
Collection work has included sources located far from the receiving laboratory or review team. The source state determines the method. A suitable live computer may be collected through a case-specific encrypted agent, while a switched-off system may be started into a controlled environment from prepared USB or optical media. Some devices still require attendance or another specialist route.
Before collection, the instruction records authority, the exact source, the operator at the device, what is to be acquired and how the result will be transferred. The person at the device follows documented steps; forensic decisions remain with the examiner. Where the method allows, the collection is verified, encrypted and handed over with relevant hashes and a record of any exceptions.
This gives the receiving examiner or provider a clear account of what was requested, what the method could access and what was actually delivered.
Case-specific advice
Every new instruction starts with its own evidence
These examples show the types of questions and material that have arisen in practice. They are not templates for the answer in a new matter. Source condition, access, retention, procedural setting and the precise question can all change what work is possible and worthwhile.
Start with the evidence question
Discuss the question and the evidence available
Send the party names, the question, the types of source available and the deadline. Do not send evidence or confidential case details through the public form.

