Computer Forensics

Valkyrie provides forensic imaging and examination of laptops, desktops, USB drives and servers to establish what happened and when. Computers keep a detailed record of activity, much of which users never see and cannot easily erase.

Preserving the evidence first

We connect drives through hardware write blockers and create verified forensic images, so the original data is never changed. All analysis is carried out on the copy, and every step is documented.

Questions computer forensics can answer

  • Did a departing employee copy files to a USB drive or personal cloud account?
  • Was a document created, edited or backdated, and by whom?
  • What files were deleted, and when?
  • Which websites, applications and accounts were used?
  • Was the computer used at a particular time, or accessed remotely?

Typical instructions

Theft of confidential information and breach of restrictive covenants, disputes over the authenticity of documents, internal misconduct investigations, and matters where a party denies sending or receiving material.

Before you contact us

Should we keep using the computer?

Ideally not. Every login and file change can overwrite useful evidence. Leave it as it is and speak to us about collection.

Can you tell if a document was backdated?

Often, yes. File system records, document metadata and related activity can show when a document really came into existence.

Findings can be presented in an expert witness report. Related services: data recovery and e-discovery and disclosure. Contact us to arrange collection.

Valkyrie Updates

News

Stay informed with the latest insights, expertise and innovations in the world of security with Valkyrie’s news, reports and white papers