Skip to main content
Write blocker with a connected hard drive in front of a screen showing a file system analysisAI-generated

Service

IT forensics

Digital activity leaves traces in several places at once: in the file system, in system logs, in application databases and in the accounts used. IT forensics brings these traces together into a timeline that answers a defined question.

What is examined

  • File systems and deleted or partially overwritten file remnants
  • System and application logs, execution traces and scheduled tasks
  • User accounts, login events and connected devices
  • Application databases, mail stores and browser artefacts

How the examination is carried out

  1. 1.Acquisition through a write blocker, with cryptographic hashes of the resulting image
  2. 2.Analysis exclusively on the secured copy, using two independent tools where the finding is critical
  3. 3.Manual review of automated results before any statement is made
  4. 4.Documentation of methods, tool versions, findings and limits

Technical limits

These limits are stated before the instruction, not afterwards.

  • Overwritten storage areas cannot be reconstructed.
  • Logs are retained only for a limited period and may already have rotated.
  • Encrypted data without a key or lawful access remains unreadable.
  • Content held only by a provider cannot be obtained by technical means alone.

FREQUENTLY ASKED QUESTIONS

IT forensics: frequently asked questions

How findings are recorded from intake to assessment is set out under documented evidence preservation and chain of custody.

Equipment used

Systems used in this examination

Next step

Discuss your case

Describe the situation briefly. We will say what can realistically be established, and what cannot.

+49 221 99981 490ContactBook an appointment