Overview
BlueTrace can assist with forensic examination of supported Windows and macOS systems, internal or external storage media, and related digital artifacts. The objective is to preserve relevant information and answer specific investigative questions without unnecessary alteration of source evidence.
Common reasons clients request this service
- Suspected copying or deletion of company files
- User activity and timeline questions
- Review of external storage usage
- Recovery or analysis of relevant deleted data
- Technical review of a computer involved in litigation or an internal investigation
What the engagement can include
▣
Forensic Acquisition
Documented acquisition or imaging appropriate to the media and scope.
⌕
Artifact Analysis
Review of relevant file-system, user, application, and operating-system artifacts.
▤
Reporting
Clear findings, supporting details, and technical documentation tailored to the engagement.
The appropriate forensic method depends on the device, account, legal authority, technical condition, and objectives of the matter. Scope is confirmed before work begins.

