A resignation to a rival, a handed-back laptop, one question to answer: had company data gone with them? A forensically sound investigation in OSForensics.
When a salesperson quit a Guildford company to join a direct rival, the firm suspected the worst: that the client database and current price lists had been copied before the laptop came back. They couldn’t prove it, and they needed to — to a standard their solicitors could rely on. The question was narrow and specific: had data left the business, and by what means? Answering it, and evidencing the answer, was what they instructed us to do.
The soundness of the whole exercise depended on how the evidence was handled, so the laptop was never examined directly. Our first act was to make a forensic duplicate of the returned Windows 10 machine: a write-blocked, hash-checked .E01 acquisition — the PC3000 doing the job on any disk that isn’t fully stable. That done, the hardware was sealed in a bag and stored, and from there we only ever looked at a read-only mount of the duplicate. OSForensics ran the analysis with its audit log on, making every step we took reproducible and tamper-evident.
Everything hinged on the file-activity record, and it was unambiguous: on one evening — forty-eight hours before the resignation — the client database and a batch of price-list spreadsheets had been written out in quick succession. What device received them showed up when we lined that evening against the machine’s USB history, which OSForensics rebuilds from Windows event logs alongside the USBSTOR entries in the registry: a SanDisk stick, logged by serial number, connected just after the files were exported and unplugged a short time later. Email and web traffic filled in the motive and the second channel — the user’s OST mail store, once indexed, held two messages to a private address with a price list attached, and the browsing record from the same minutes captured a webmail login and a file sent up to personal cloud storage. A number of the exports had been deleted afterwards; those we recovered by carving them from the image.
OSForensics produced the deliverable itself: a hash-verified report that drew every thread into one place — the exported files and when they were written, the SanDisk device and its timestamps, the two emails, the cloud upload, and the deletions we’d recovered — each anchored to the audit trail. That report went to the firm’s legal team to act on as they saw fit. Start to finish, five working days. Workplace investigations we undertake only for the owner of the equipment, and only on written instruction.
OSForensics · PC3000 — a write-blocked, hash-verified image examined read-only; USB history, file timeline, mailbox and recovered deletions drawn into an audit-trailed report. For the equipment’s owner only, on written instruction.
Send us your device for a free diagnostic, and tell us a little about what happened — an engineer will review it and confirm your exact quote in writing before any work begins.
Getting your data back begins with getting the device to us. Pack it up safely, pop your contact details inside, and send it over — once we’ve run the free diagnostic, we’ll confirm your exact price in writing before any work starts.
Posting it? A tracked, insured service is what we’d recommend. Rather drop it in? You’re welcome Monday to Friday, 9am to 5:30pm — just package the device up as above first.
Want a bit more detail first? Fill in the form with more about your issue and an engineer will review it and send you a custom quote.
We’ll be in touch shortly. For anything urgent, call 01483 901310.
Yes. USB-device history, timelines of file activity, mailbox examination and recovery of deleted files together show what happened — all preserved to a standard that stands as evidence.
It’s built from a write-blocked, hash-verified image with a complete audit trail, and written to suit solicitors or a tribunal.
From £800 plus VAT. These workplace investigations we take on for the equipment’s owner alone, on written instruction.
Start with an instant online quote, or call and talk it through with us first. You'll have a clear, fixed price before any work begins.