Where copying is suspected the questions are narrow. Which device. Connected during which hours. Carrying what. Windows supplies most of it without being asked. Off a verified copy we lift those answers and put them in order, for employers right across the North East, from processing plants at Peterhead and Fraserburgh to survey operations at Dyce.
◇ Footing first. Bench time after. The free diagnostic opens the job, a written scope follows it, and forensic fees clear ahead of any examination. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
Sticks, cards and portable drives land at the centre of more arguments than anything else we get sent.
Windows makes a note of each portable device it meets. USBSTOR takes maker, model and serial number for each stick, card reader or external drive. setupapi.dev.log pins each first appearance to the second. Other registry entries connect a device to whichever profile mounted it, and record the last sighting. Extracted off a verified copy, that register spans the machine's whole working life, hardware included that nobody thinks to mention until it appears on a schedule.
Presence is one thing. A case normally needs movement. LNK records and jump lists capture company documents opened from whatever letter the portable volume was handed, with paths and times still attached. Shellbags keep the folder tree somebody walked through on it, long after the hardware disappeared. The change journal orders the surrounding activity minute by minute. Produce the stick as well and its own image finishes the account: current contents, arrival times, and whatever has been stripped off since.
Timestamps repay attention, because copying leaves a signature all of its own. Copy a file to a second volume and the created stamp records the moment of the copy while the modified stamp travels along untouched with the contents. So a document apparently created at 02:07 but last modified three years earlier is reporting the copy and not the writing. Put it next to the register and the journal and every transfer acquires a date. A run of them outside working hours seldom looks like housekeeping.
This discipline reaches well past sticks. SD and microSD out of cameras, dashcams and survey drones. CF cards from older equipment. External SSDs. All of it goes through identical imaging and identical analysis. Memory card forensics works in both directions here: documents traced onto a card, and deleted stills and video recovered off one. Where the card is the whole case, it gets worked next to whichever machine wrote to it, so each account keeps the other honest.
Custody and method belong to the forensic recovery hub. For dating a deletion, carry on to deleted-file forensics. The employer casework this feeds is employee data theft. Figures are on the prices page.
Each finding arrives with a date, the account it belongs to, and its supporting artefact.
Each stick, card and drive that machine has ever met, by maker, model and serial.
First appearance and last sighting for each device, fixed to the second.
Documents opened off the device letter, with paths and hours attached.
The directory structure walked through on the device, held in shellbags.
Stamp patterns that put a date against each copy onto the device.
The media captured in its own right, with its deleted contents returned.
Each instruction opens on the free diagnostic. Allow 2 working days from the date a device reaches this bench. Forensic casework sits outside no fix, no fee. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. You will find both figures repeated on the prices page, and we take nothing until a scope is agreed in writing.
Portable-media work runs across company machines and company-issued media, or on written instruction from a solicitor. Three doors in, and we have never found a fourth. Kit the business itself owns. A written instruction out of a solicitor, an insurer or from the court. Or else a device that genuinely belongs to the client, which in a matrimonial matter takes in one held between the two of them. Nothing gets hacked at this bench. Live traffic is never intercepted. Where the instructing client holds no right to look inside a device, we hold none either.
A stick, plus whichever machine wrote to it, is best looked at as a pair. Ring 0800 689 0668 and we will settle the set between us. Collection is not on offer, so every item comes to Edinburgh tracked and insured, or across the counter, and enters the custody log on signature.
Still bolted into a laptop, desktop, MacBook, iMac, server or CCTV / DVR box? Get the hard drive or SSD out first. The bare drive travels on its own. Stripping machines down is not a job this lab takes on. Flash soldered to a motherboard, as on Apple Silicon Macs and a couple of very thin laptops, is our one flat no: if it will not unbolt, it cannot be worked on.
↓ Print the shipping & booking-in form (PDF)
Address it for the attention of Edinburgh Data Recovery. From Aberdeen that is roughly 130 miles and two and a half hours down the A90, or next working day by tracked post if you would rather not make the run. You get a call the moment it is booked onto the bench.
Not sure what belongs in the box? Ring 0800 689 0668 before you tape it shut, or work through the free online diagnostic.
Leave the machine where it stands, keep hold of the stick, and ring the freephone.