Computer Forensics

Computer Forensics

Preservation and analysis of computers and storage media to identify relevant files, activity, and system artifacts.

Overview

BlueTrace can assist with forensic examination of supported Windows and macOS systems, internal or external storage media, and related digital artifacts. The objective is to preserve relevant information and answer specific investigative questions without unnecessary alteration of source evidence.

Common reasons clients request this service

  • Suspected copying or deletion of company files
  • User activity and timeline questions
  • Review of external storage usage
  • Recovery or analysis of relevant deleted data
  • Technical review of a computer involved in litigation or an internal investigation

What the engagement can include

▣

Forensic Acquisition

Documented acquisition or imaging appropriate to the media and scope.

⌕

Artifact Analysis

Review of relevant file-system, user, application, and operating-system artifacts.

▤

Reporting

Clear findings, supporting details, and technical documentation tailored to the engagement.

The appropriate forensic method depends on the device, account, legal authority, technical condition, and objectives of the matter. Scope is confirmed before work begins.

Need help with digital evidence?

Tell us what happened and what devices or accounts may be involved.

Request a Consultation