top of page

Computer Forensic Examinations

We use imaging tools that let us quickly assess electronic evidence to determine if further analysis with additional Forensic Software and Techniques are warranted. We also create perfect copies (forensic images) of computer data without making changes to the original evidence.

​

We can preview files and folders on local hard drives, network drives, floppy diskettes, Zip disks,

CDs, and DVDs. We create forensic images of local hard drives, floppy diskettes, Zip disks, CDs, and DVDs, PREVIEW the contents of forensic images stored on the local machine or on a network drive, EXPORT files and folders from forensic images, and GENERATE hash reports for regular files and disk images (including files inside disk images)

​

Important: When we create a forensic image of a hard drive, we utilize a hardware/ software-based, write-blocking device. This ensures that your operating system does not alter the suspect’s hard drive when you attach the drive to your computer. We use a data acquisition tool that can be used to quickly preview evidence and, if the evidence warrants further investigation, create a forensically sound image of the media. To prevent accidental or intentional manipulation of the original evidence, we make a bit-for-bit duplicate image of the media.

​

The forensic image is identical in every way to the original, including file slack and unallocated space or free space. This is to insure a precise and accurate Forensic Examination.

bottom of page