A file has two histories: the life it led and the way it ended. Both can usually be recovered. From recycle-bin records to journal entries and shadow copies, we establish what existed on a machine, how it was used, and precisely when — and by what means — it was deleted. For York employers, solicitors and private clients with a deletion in dispute.
◇ Method before speed. The free assessment and a written scope come first; forensic fees are settled in full before any examination starts. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
The examination serves any matter where what was removed — and when — carries weight.
Deletion comes in grades, and each grade leaves a different record. A file sent to the recycle bin gains a small metadata record holding its original path, its size and the exact moment of deletion — and that record routinely survives the emptying of the bin. A permanent deletion skips the bin but only releases the file's entry in the file system's index; the content remains on disk until other data happens to overwrite it. Which grade occurred, and when, is usually the first finding of the examination — and it often says something about intent.
Timeline reconstruction in digital forensics is the work of putting every recorded event into one dated order, from sources that check each other. The NTFS master file table holds each file's created, modified and accessed times; the change journal records operations — creation, rename, deletion — as they happened; the file system's transaction log adds fine detail around the moments that matter; and Windows event logs show who was signed in, and what was opened or altered, in the hours before a deletion. Read against creation dates, deletion timestamps answer the useful question: was this housekeeping, or was it timed?
Workstations quietly keep more than one past. Volume Shadow Copy snapshots — created for restore points and backups — hold earlier states of the disk, complete with files that were later deleted and versions from before an edit. Comparing a snapshot with the current volume shows exactly what disappeared between two dates, which is often the cleanest exhibit a deletion case can produce: the file present on the 3rd, absent on the 10th, and the journal recording the removal on the 7th.
Wiping software is not quiet. The anti forensics detection techniques we apply start from the traces the tools themselves leave: installation records and prefetch entries naming the program, execution timestamps, the characteristic patterns overwriting leaves on disk, and the gap where expected artefacts should be. A wipe destroys content but manufactures evidence — which tool ran, when, under which account, and what it missed. Partial and interrupted runs are common, and what survives them is recovered in the ordinary way.
The imaging and custody discipline behind this page lives at the forensic recovery hub. Deletions tied to removable media continue on USB device forensics; whole-machine capture is covered under workstation deep imaging; fees sit on our prices page.
Each source corroborates the others; the timeline stands on their agreement.
Original path, size and deletion moment, surviving the emptied bin.
Created, modified and accessed times for present and deleted files.
Creations, renames and deletions in operation-by-operation order.
Sign-ins and access around each deletion, from the system's own logs.
Earlier states of the volume, holding files deleted since.
Which utility ran, when, under which account — and what it missed.
The free diagnostic that opens every case is completed within 2 working days of arrival; forensic casework itself is not a no fix, no fee service. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. Both figures are itemised on our prices page, and the written scope is agreed before payment is taken.
Deletion casework proceeds on company-owned machines, your own devices, or a solicitor's instruction. Instructions are accepted on three footings only: equipment the company itself owns; the instruction of a solicitor, insurer or court; or devices that are genuinely the client's own — including jointly owned machines in matrimonial matters. We do not hack, we do not intercept live communications, and we do not examine a device the instructing client has no right to examine.
Every day of ordinary use costs a deletion case something, so take the machine out of service and call 0800 689 0668 today. It reaches our Leeds location tracked next-day or by hand, and enters the custody record at the signature.
Is the drive still inside a computer, laptop, MacBook, iMac, CCTV / DVR or server? Take the hard drive or SSD out first and post the bare drive on its own — removing drives from machines isn't a service we offer. Storage that's soldered to a motherboard (Apple Silicon Macs, certain slim laptops) is the one thing we can't work on: if it doesn't come out, it can't come in.
↓ Print the booking-in & shipping form (PDF)
Address the parcel for the attention of Leeds Data Recovery — about 40 minutes from York via the A64 and A1(M), or next working day by tracked post. You'll hear from us the moment it's booked onto the bench.
Not certain what to pack? Ring 0800 689 0668 first, or run the free online diagnostic.
Stop using the machine, ring the freephone, and let the timeline speak for itself.