Forensic Investigation & Analysis

Our forensic investigation services ensure that no stone is left unturned in uncovering critical evidence.

Our forensic investigation services ensure that no stone is left unturned in uncovering critical evidence. We perform detailed analysis of various data sources, including:

  • Log File Analysis: Reviewing system logs to identify patterns, user activity, and critical actions.
  • Unallocated Space & File Recovery: Searching for deleted files, unallocated space, and performing file carving to recover overwritten or missing files.
  • Hibernation & Volatile Memory Analysis: Examining memory dumps and hibernation files to capture running processes, network connections, and active malware.
  • Link File Analysis: Identifying file/document access by user.
  • Registry Analysis: Analyzing system registry data to uncover USB history, user activity, system processes, and other hidden information.
  • Timeline Analysis: Using system and file activities, which may include prefetch analysis, to create a detailed sequence of events.
  • Anti-Forensics Detection: Identifying and analyzing attempts to wipe data or tamper with metadata, timestamps, or other information.
  • Email Analysis: Investigating email timeframes, key recipients, and terms used, across both local and web-based systems.
  • Internet History: Reviewing user web searches, visited sites, and browsing patterns to identify patterns of use/abuse.
  • Document Analysis:  Reviewing document revisions, ownership changes, timestamps, and file transfers to identify unauthorized access or alterations.
  • Restore Point Analysis: Investigating system restore points to uncover activity and any potential anti-forensic measures.
  • System Profiling: Profiling systems to define user behaviors, recent files, applications in use, and activity patterns.  (Very high level.)
  • Cell Phone Data Extraction: Extracting data from mobile phones, including text messages, SMS, contacts, call history, emails, whatsapp messages, GPS history, Apps used and much more.

Need Help? Contact Us

kjones@dwforensics.com

(214) 566-7800

need help?

FAQ’s

How long will it take to image my computer or cell phone?
The time to image a computer or cell phone all depends on the amount of data and the storage capacity. Computers may take 4 or more hours while cell phones can typically be imaged within two hours but could run longer.
Can I use my cell phone during imaging.
The phone must remain in airplane mode while imaging so they phone; therefore, you will not be able to use it during the imaging process.
How long will it take to collect my email?
The time to collect email varies from one email provider to another and could take a few hours or run overnight. Fortunately, you can continue to use your email during the collection process.
Can I still use my email during the data collection?
Yes, you can still use your email during the data collection.
Is my data secure and how long will you keep my data?
Typically, we must keep the data throughout the entire legal process. It is not until we receive a written request from legal counsel do we then destroy the data. The data collection is saved on encrypted hard drives and is secured in our vault. Our building also maintains a security presence and remained locked afterhours requiring keycards to gain access to the building.
Will you be going through and reviewing my data?
Typically, no, we do not review your data. Most cases have a defined protocol that has us search the data and provide only those emails or documents that contain specific words or phrases. We then provide only those emails and documents to counsel that have those specific, targeted words and phrases.