Workstation Deep Imaging

A returned laptop gets one forensic moment and it sits between hand-back and rebuild. Taken in that window, read behind a write-blocker into E01 containers and checked on SHA-256, it answers questions for years afterwards. Put back into service, it answers fewer every week. For employers running crew rotas out of Dyce and the heliport the rule is short enough: questions keep, images do not.

Footing first. Bench time after. The free diagnostic opens the job, a written scope follows it, and forensic fees clear ahead of any examination. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// machines that belong on the list

When to capture before anything else happens

Any one of these puts a machine on the list, a long way in front of the rebuild queue.

IT are holding a leaver's laptop, ready to hand it to somebody else
A machine tied to a dispute is queued for rebuild or for scrapping
A BitLocker or FileVault device is back and its user has gone
Chat history or deleted material may be wanted further down the line
Questions have been raised over VPN, remote access or browsing
There is a suspicion the drive was erased on purpose

Capture first, reissue the laptop afterwards

The sums here are lopsided. Image it today, disk taken behind a write-blocker into E01 containers and checked on SHA-256, and the cost is a small share of what that same material fetches once a dispute exists to spend it against. Hardware goes straight back on the floor afterwards, since the evidence has stopped living on it. Leave the image untaken, pass the laptop along, and every day of the next person's work settles over the previous user's traces. Companies that make leaver captures routine are never the ones explaining a gap.

What a full capture hangs on to

A great deal more than the documents. Cache, cookies and browsing history put research and uploads back together. Temporary folders keep drafts and copies that nobody ever chose to save. Whatever sat in memory leaves fragments behind, an open document, a chat window, now and then a credential, and those survive inside the pagefile and hibernation file. Local caches under Teams and Slack return conversations long since deleted out of the applications. VPN and connection logs record which networks the machine joined and when. A rebuild removes every bit of that. A capture keeps it.

Locked machines, taken while it is still possible

Encryption rewards moving early. A device under BitLocker or FileVault wants imaging while keys remain in escrow and passwords are still known, which means before the leaver's account is closed, before directory tidying, and before a rebuild clears the TPM. Where a Windows volume is live and already unlocked there is a second road in: Volume Shadow Copies taken off the running system, which get round the encryption problem because the volume is already open in front of you. Work on encrypted volumes is Forensic-classed and, as with the rest of this page, payable upfront as soon as the scope is settled.

Erased, or said to have been

Any claim of wiping gets tested, not taken on trust. Boot tools and erase utilities, DBAN among them, drop traces behind them. Boot records. Signatures particular to the tool. Whatever pattern an overwrite lays down across the platters. Timing that can be measured against the rest of that week. Runs that stopped halfway are common enough and leave entire regions still recoverable, while a hardware erase instruction can be checked off against the drive's internal logs. Where the wipe really did complete, we say so and supply the date, since erasing a disk deliberately with proceedings coming is itself a finding.

Verification and custody belong to the forensic recovery hub. For what deletion evidence looks like on a copy, see deleted-file forensics. The duty to preserve is legal hold and chain of custody. Figures are on the prices page.

// what one capture holds

Still worth having two years on

Taken once, verified once, and sitting there for whatever the dispute asks later.

E01 containers

The entire disk, in a format other examiners can open and check.

Hash values

SHA-256 proving the image, and each copy off it, has not been altered.

Browser traces

History, cache and cookies, which rebuild research and uploads.

Memory fragments

Pagefile and hibernation contents: documents, chats, credentials.

Chat caches

Local Slack and Teams stores, with removed conversations returned.

Connection logs

VPN and network traces placing the machine on a given network at a given hour.

// the price, and who we may act for

Forensic fees, and the footing underneath them

The money, stated plainly

Each instruction opens on the free diagnostic. Allow 2 working days from the date a device reaches this bench. Forensic casework sits outside no fix, no fee. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. Encrypted volumes, BitLocker among them, are Forensic-classed work and payable upfront on the same footing. You will find both figures repeated on the prices page, and we take nothing until a scope is agreed in writing.

The footing we need

Imaging runs on machines the company owns, on hardware of your own, or under an instruction from a solicitor. Three doors in, and we have never found a fourth. Kit the business itself owns. A written instruction out of a solicitor, an insurer or from the court. Or else a device that genuinely belongs to the client, which in a matrimonial matter takes in one held between the two of them. Nothing gets hacked at this bench. Live traffic is never intercepted. Where the instructing client holds no right to look inside a device, we hold none either.

// getting your device to us

Getting it to the bench — plainly done

Give us the machine count, and your position on encryption, when you ring 0800 689 0668, and the capture gets scoped in writing. No collection service is offered. Drives travel tracked and insured, or come across the counter in Edinburgh, and custody runs from the signature.

Still bolted into a laptop, desktop, MacBook, iMac, server or CCTV / DVR box? Get the hard drive or SSD out first. The bare drive travels on its own. Stripping machines down is not a job this lab takes on. Flash soldered to a motherboard, as on Apple Silicon Macs and a couple of very thin laptops, is our one flat no: if it will not unbolt, it cannot be worked on.

  • Bubble wrap, then a rigid box or padded envelope packed tight enough that nothing rattles. Keep the cables, caddies and power bricks at home.
  • Print the shipping & booking-in form (PDF). Name, mobile number, two lines on what went wrong. In the box with the drive.
  • Royal Mail Special Delivery is tracked and insured door to door. Your own courier account does the same job if you would rather use it.
  • Handing it over yourself instead? Reception takes drop-offs at the address below, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Edinburgh Data Recovery

4 Redheughs Rigg
Westpoint, South Gyle
Edinburgh, EH12 9DQ

↓ Print the shipping & booking-in form (PDF)

Address it for the attention of Edinburgh Data Recovery. From Aberdeen that is roughly 130 miles and two and a half hours down the A90, or next working day by tracked post if you would rather not make the run. You get a call the moment it is booked onto the bench.

Not sure what belongs in the box? Ring 0800 689 0668 before you tape it shut, or work through the free online diagnostic.

// workstation imaging · asked before instruction

What IT teams check first

Usually, and that is precisely why capture comes before reissue. Once the copy is verified it carries the evidence, and the hardware reverts to being an ordinary laptop. One exception: a live dispute in which the device may itself be called for. Your solicitor makes that call, and we keep it sealed meantime.
Weakened, not ruined, and the report will say so. That session shifted some dates. It did not undo the registry, the journals, the caches or unallocated space. Write down what got done, and when, stop at that, then take the image.
Leave the directory alone for now. Recovery keys are usually still held in Intune, Azure AD or the Microsoft account attached to that machine. Image first, unlock against the copy afterwards, and do it before accounts get closed and passwords cycled. It is Forensic-classed work, scoped after the free diagnostic and payable upfront.
Test the claim. A fair share of advertised wipes turn out partial, interrupted, or simply misconfigured, and whole regions come back. On top of that the wipe can be named, dated and attributed, which in litigation is now and then worth more than the files were. A wipe that genuinely completed is reported as exactly that.

Rebuild it next week. Image it first.

A single capture holds every answer left in that machine. Ring the freephone.