Computer Forensics
Law & Forensics recovers, preserves, and analyzes digital evidence from computers, mobile devices, and other media to court-admissible standards, and presents the findings clearly through expert reports and testimony.
Computer Forensics capabilities
Digital Evidence Recovery
We retrieve critical electronic data from a wide range of devices, including deleted files, emails, and text messages. Our examiners apply industry-leading tools and defensible methods to preserve the integrity of evidence and protect its admissibility in court.
Data Recovery from Damaged Media
Our team recovers data from damaged or corrupted hard drives, smartphones, and tablets, drawing on deep knowledge of storage formats, encryption methods, and recovery techniques to extract information that would otherwise be lost.
Forensic Data Analysis
We use advanced analysis tools to search and extract relevant information such as deleted files, email archives, and web browsing history, then analyze that data to identify patterns and uncover hidden information central to a matter.
Expert Witness Testimony
Our examiners testify and provide expert reports on the authenticity of digital evidence, the methods used to collect and analyze it, and its reliability, translating complex technical findings into clear, understandable terms for the court.
Proprietary Processes and Tooling
We have developed proprietary processes, software, and workflows that allow us to process and review large volumes of data efficiently while ensuring the accuracy and reliability of every forensic analysis.
Computer Forensics — matters we are engaged for
A laptop is wiped between notice and collection
The custodian ran a cleanup tool, reinstalled the operating system, or simply deleted the folder. What survives is rarely the file itself — it is the registry, the journal, the shadow copies and the link files that record the file having existed. Establishing what was destroyed, and when, is usually more valuable than recovering it.
Two experts disagree about what the artifacts mean
The other side's report reads plausibly and reaches the opposite conclusion. The work here is a technical read of their method: what they examined, what they did not, and whether the artifacts they relied on actually support the inference drawn from them.
Failed or encrypted media holds the only copy
A drive that will not mount is not the same as a drive with no data. Physical recovery, chip-off work and decryption against a lawfully obtained credential are separate questions, and the answer determines whether the evidence exists at all.
The collection itself is challenged
Opposing counsel attacks how the image was taken rather than what it showed. Hash verification, write-blocking, and a chain of custody that survives a deposition are what make that attack fail — which is why they have to be right before anyone looks at the contents.
Computer Forensics — frequently asked questions
What types of devices and data can you recover evidence from?
We extract and analyze electronic data from computers, smartphones, tablets, and other digital media, including deleted files, emails, text messages, email archives, and web browsing history, even from damaged or corrupted devices.
Will the recovered evidence hold up in court?
Yes. We follow best practices designed to preserve the integrity of digital evidence and protect its admissibility, and our examiners can testify to the methods used to collect and analyze it as well as to its reliability.
Do you provide expert witness testimony?
Our forensic examiners have extensive experience providing expert reports and testimony in legal proceedings worldwide, addressing the authenticity of digital evidence, collection and analysis methods, and reliability.
How does a computer forensics engagement begin?
Each engagement starts with an in-depth assessment of your needs, followed by a customized recovery and analysis plan tailored to the specifics of the matter, your goals, and your budget.
Who do you typically work with?
We have conducted hundreds of forensic investigations for clients across many industries, including Fortune 500 companies, government agencies, and law firms.
Computer Forensics — questions, terms and comparisons
Questions answered
Terms defined
Digital Forensics experts who testify to this work
Full expert panel →
J-Michael Roberts
Senior Director
Digital Forensics · Incident Response · Malware Reverse Engineering

Daniel B. Garrie
Founder
Digital Forensics · Expert Witness Testimony · Incident Response

Roland Cloutier
Expert Consultant
Incident Response · Expert Witness Testimony
Our experts serve as court-appointed special masters, forensic neutrals, and arbitrators — 40 appointments are listed by matter and citation.
Computer Forensics case results
Electric Utility / Power Generation
Forensic Attribution Halts a Departing Engineer's Theft of Grid Design Data at an Electric Utility
Logistics & Freight
Insider Theft of Proprietary Routing and Pricing Models Traced and Proven at a National Logistics Carrier
Public Research University
Forensic Attribution of Faculty Research-IP Theft at a Public Research University

