data recovery forensicsData Recovery Forensics captures, processes, and investigates data from computers using a methodology whereby any evidence discovered is acceptable in a Court of Law. Data recovery forensics evidence must not be damaged, destroyed or otherwise compromised by procedures used to investigate the computer, otherwise it may be rendered inadmissible in court. Increasingly used in civil and criminal litigation, computer forensic data recovery is a science that involves the preservation of computer related data, the extraction of evidence, and the identification of leads.

Computer forensics involves finding specific files or file types, deleted or hidden files, partially overwritten files (known as slack space), email, internet chat, and other residual data. It can provide a timeline of file manipulation and activity. Being able to effectively deal with this data, in the course of discovery, can be instrumental to success at trial or negotiation. In many cases, the data plays a pivotal role in prosecutions.

Used by professional investigators, police, IT security staff, and customs officials, this forensic science has developed in conjunction with investigating authorities in the UK, Europe and North America. All forensics recovery work must be meticulously documented and the procedures fully auditable.

Developments in forensic computing now permit hidden or deleted computer data to be found quickly, reliably and efficiently. If evidence lies in hidden, system files, deleted or partially overwritten areas anywhere on the storage medium, computer forensic systems will find it. Even computer disks destroyed by fire can be read under an electron microscope.

Mail may be stored on a local hard drive, a network device, or a removable device. Many email clients will save a copy of outgoing messages, so both the sender and the recipient may have a copy of each message. Mail may also be stored on a dedicated mail server, either awaiting delivery or as permanent storage. E-mail has become one of the primary mediums of communication in the digital age, and data recovery forensics targets the vast amounts of evidence to be found there.

Back to the top of Data Recovery Forensics.