Computer forensic collection.
Full or targeted forensic imaging of Windows and Mac workstations — preserving documents, deleted files, browser history, and user activity artifacts with court-tested methodology.
What gets preserved.
- All documents and files (current and deleted)
- Browser history, downloads, and bookmarks
- Email client data (Outlook, Apple Mail)
- USB and external device connection history
- System event logs and user activity artifacts
- Recycle bin and recently deleted files
- File access and modification timestamps
- Chain-of-custody report & hash verification
Common matters we support.
When the evidence lives on a laptop or workstation.
Trade Secret & IP Theft
Documenting file access, copying to external drives, or email exfiltration before a departing employee's device is wiped.
Employee Misconduct
Browser history, communications, and user activity on company-issued hardware when HR or legal has concerns.
Fraud Investigations
Document creation timelines, file modification metadata, and deleted records that reveal intent or concealment.
Wrongful Termination
Preserving the state of an employee's computer at the time of termination to establish a factual record.
Contract Disputes
Document authenticity questions — when did a file actually exist, who created it, and was it altered after the fact?
Divorce & Family Law
Financial records, hidden accounts, or communications on a shared or personal computer when consent exists.
About computer collections.
What's the difference between a full image and a targeted collection?
Can this be done remotely without shipping the computer?
What if the hard drive has been reformatted or the computer wiped?
Does forensic collection affect the computer's normal operation?
Ready to preserve this computer?
Book a free 15-minute scoping call. We'll confirm the right approach and give you a fixed price on the spot.
