
Forensic Capability Across Every Major Source of Digital Evidence
We describe what we can examine and how we examine it. Our approach is vendor-neutral: the method, the documentation and the examiner determine the result.
Forensic capability across every major source of digital evidence.
We describe what we can examine and how we examine it. Our approach is vendor-neutral: the method, the documentation and the examiner determine the result.
Mobile Device Forensics
Structured examination of smartphones and tablets, from acquisition through communications and location analysis.
- iOS and Android investigations
- Mobile evidence acquisition
- Device data analysis
- Deleted-data recovery
- Application analysis
- Communications analysis
- Location data
- Cloud-connected evidence
- Mobile evidence reporting
Computer & Endpoint Forensics
Artifact-level examination of workstations and removable media to reconstruct user activity over time.
- Desktops, laptops and workstations
- Removable media
- Operating-system artifacts
- Deleted files
- Browser activity
- User activity
- Timeline reconstruction
- Endpoint investigations
Cloud Forensics
Preservation and analysis of evidence held in cloud accounts, collaboration platforms and hosted email.
- Cloud-account investigations
- Email environments
- Cloud storage
- Application data
- Account activity
- Cloud evidence preservation
- Cross-platform evidence correlation
Digital Media Forensics
Investigation of image, audio and video evidence at both single-file and repository scale.
- CCTV and surveillance video
- Body-worn video
- Dashcam footage
- Photographs and imagery
- Audio evidence
- Video evidence
- Multimedia investigation
- Large-scale media review
- Media authenticity assessment
Vehicle & Location Forensics
Recovery and interpretation of movement, journey and telemetry evidence from vehicles and navigation systems.
- Vehicle data
- GPS evidence
- Navigation systems
- Location history
- Connected-vehicle evidence
Drone & IoT Forensics
Examination of device-generated data from unmanned systems and connected environments.
- Drone evidence
- Connected devices
- IoT systems
- Device-generated data
- Location and telemetry evidence
Cyber & Incident Investigations
Forensic reconstruction of security incidents, from initial access through to data movement.
- Data breach investigation
- Ransomware investigation
- Insider threat
- Data exfiltration
- Endpoint compromise
- Incident reconstruction
- Post-incident forensic investigation
Digital Fraud Investigations
Tracing digital and transactional evidence across accounts, documents and communications.
- Financial fraud
- Transaction analysis
- Digital evidence tracing
- Employee misconduct
- Corporate fraud
- Document and communication analysis
From Images and Video to Investigative Evidence
Media evidence arrives in mixed formats, from mixed sources, often in volume. We normalise, catalogue and examine it as a single evidential set.
Digital Media Investigations
From Images and Video to Investigative Evidence
Media evidence arrives in mixed formats, from mixed sources, often in volume. We normalise, catalogue and examine it as a single evidential set.
- CCTV analysis
- Body-worn video
- Dashcam footage
- Mobile video
- Image analysis
- Audio analysis
- Video analysis
- Multimedia evidence review
- Large-scale media investigation
- Evidence verification
Support across the lifecycle of a matter.
- ESI collection
- Evidence preservation
- Forensic imaging
- Evidence processing
- Document review support
- Litigation support
- Expert reports
- Expert testimony
- Chain-of-custody documentation
Recovering data where recovery is possible.
- Deleted data recovery
- Damaged storage
- Corrupted devices
- Failed storage media
- Mobile data recovery
- Forensic preservation
- Recovery assessment
Recovery outcomes depend on the condition of the media and the nature of the data loss. We begin with an assessment and state honestly what is, and is not, achievable.
Technology-Enabled Forensics
We combine specialist forensic expertise with industry-leading investigative technologies to examine complex digital evidence.
- Forensic acquisition technologies
- Mobile evidence technologies
- Computer forensic technologies
- Digital-media analysis technologies
- Evidence-processing technologies
- Secure case-management technologies
- Forensic laboratory technologies
- Advanced data-recovery technologies
Discuss a digital investigation with our examiners.
From a single device to multi-source investigations involving thousands of digital artifacts.
Discuss an Investigation