Call us — 01483 901310
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
Forensic recovery · explained

How does forensic data recovery work?

Forensic data recovery is recovery done so the result holds up as evidence. That means never touching the original: the drive is imaged behind a hardware write blocker, the copy is proven identical by cryptographic hash, and every step is documented. Here’s how that works, what it can uncover, and where the line sits.

Write-blocked imaging
Hash-verified
Documented chain of custody
// in one line

Recover it without changing it.

The whole point is defensibility: the original is never written to, the copy is proven identical, and the findings are recorded so another examiner could repeat them and reach the same result.

Write blocker
No writes
Hash
Proves integrity
Artefacts
Who, what, when
Custody
Documented
×Scope, up front. We recover and analyse only devices you’re entitled to examine, and we report what the evidence shows — factually, not to a desired conclusion. Forensic work is quoted from £800 +VAT after a free diagnostic.
// what makes it forensic

What makes recovery forensic.

Ordinary recovery gets the data back. Forensic recovery gets it back in a way that stands up.

The difference is defensibility. A forensic recovery begins with a hardware write blocker — a device sitting between the evidence drive and everything else that allows reads but physically blocks every write, so the original can’t be altered while it’s read. We take a bit-for-bit image of the whole drive, then verify that copy against the source with a cryptographic hash (MD5 and SHA-256) — a digital fingerprint that proves, in cold maths, the image is identical to the original and hasn’t changed since.

From then on, all work happens on that verified copy. Running analysis on the original device would change timestamps and could overwrite deleted data — the very evidence in question — which is why, forensically, it’s never done.

// the artefacts

What the analysis uncovers.

Deleted files are only the start — the operating system keeps a detailed record of activity.

The obvious part is recovering deleted files, carved from unallocated space and dated from what survives in the file system. The revealing part is the artefacts the system keeps almost everywhere: the $MFT with its created, modified and accessed timestamps; the $UsnJrnl change journal; the Windows registry hives; LNK shortcut files and prefetch records; shellbags; USB insertion history; and browser and cloud-sync remnants.

Individually these are fragments. Together they answer the questions that matter in an investigation — which files existed, when they were created or deleted, what was plugged in and when, and what was opened — the who, what and when behind the data.

// the timeline

Building a timeline.

The value isn’t any single artefact — it’s correlating them.

We correlate the metadata and timestamps from those artefacts into a single timeline that establishes what happened, and in what order. It’s also how tampering shows up: when the timestamps in one record disagree with another — a file’s claimed date against the change journal, say — backdating or deletion becomes visible. Crucially, the process is repeatable: another examiner working from the same verified image would reconstruct the same timeline and reach the same conclusions.

// chain of custody

A documented chain of custody.

Evidence is only as strong as the record of how it was handled.

Alongside the technical work, every device is logged in on arrival, its handling and return recorded, and each image tied to its verifying hash — a documented chain of custody that shows the evidence was preserved and unaltered from receipt to report. Where a matter is heading for court, HR or an insurer, the recovery and analysis are carried out to a court-ready standard, with findings reported plainly enough to stand up to scrutiny. There’s more on how we handle evidence on our data security page.

// when it’s used

When it’s needed — and the limits.

Common cases, and the scope we hold to.

Forensic recovery comes up in employee and insider cases (data taken before someone left, a company device misused), commercial disputes and litigation, fraud and misconduct investigations, insurance claims, and questions of whether files were altered or backdated. It draws on the same imaging and reconstruction as ordinary data recovery — the difference is the rigour around it. Related work like secure data destruction follows the same evidential care.

The limits are firm: we examine only devices you’re entitled to, and we report what the evidence actually shows rather than a preferred outcome. Forensic recovery is quoted from £800 +VAT after a free diagnostic, and it’s all carried out in-house, in the UK.

// questions

Forensic recovery, answered.

It’s recovering and analysing data from a device in a way that keeps it sound as evidence. The drive is imaged behind a hardware write blocker, the copy is verified against the original by cryptographic hash, and every step is documented — so the findings hold up for solicitors, HR or a court. The original is never worked on directly.

The imaging and reconstruction are similar; the difference is the rigour around them. Forensic work uses a write blocker and hash verification to prove nothing changed, analyses system artefacts and timestamps as well as files, and keeps a documented chain of custody — all so the result is defensible, not just recovered.

A write blocker sits between the evidence drive and the computer, allowing reads but physically preventing any write. It matters because simply connecting a drive to a running computer can change it — updating timestamps or overwriting deleted data. Blocking writes, and hashing the image to prove it matches the source, is the foundation of a defensible recovery.

Often, yes. File-system timestamps, the change journal, event logs and other artefacts can show when a file was created, altered or deleted, and disagreements between those records can reveal backdating. We correlate them into a timeline and report it plainly — and because it works from a verified image, another examiner could reproduce it.

Yes. We image behind a write blocker, verify by hash, and document the receipt, handling and return of every device, so the chain of custody holds up. Where a matter requires it, the work is carried out to a court-ready standard. Admissibility ultimately rests with the court, but the evidence is prepared to meet that bar.

Forensic and investigative work is quoted from £800 +VAT, after a free diagnostic and a written quote. The figure depends on the devices involved and the scope of the analysis. Everything is carried out in-house, in the UK, under an NDA where you need one.

// need it to stand up?

Evidence on a drive? Let’s handle it properly.

Tell us the devices and what’s in question — we’ll image them read-only behind a write blocker, keep a documented chain of custody, and give you a free diagnostic and a fixed written quote first.