USB & Removable Media Forensics

When copying is suspected, the useful questions are narrow: which device, connected when, carrying which files. Windows keeps most of the answers without being asked. We read them from a verified image and set them out in order — for employers from Clifton Moor to the distribution estates along the A64.

Method before speed. The free assessment and a written scope come first; forensic fees are settled in full before any examination starts. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// when removable media is the issue

The situations this examination settles

A stick, a card or a portable drive sits at the centre of more disputes than any other exhibit.

A memory stick was seen in use during someone's final weeks
Device records show serial numbers nobody can account for
A leaver says the drive was personal and so were the files on it
A camera or dashcam card holds material a case now turns on
A portable SSD went home and has not come back
A flat denial that anything was ever plugged in at all

The register of everything ever plugged in

Windows records each removable device it meets. The USBSTOR registry key holds the maker, model and serial number of every stick, card reader and portable drive connected to the machine; setupapi.dev.log dates each device's first appearance to the second; further registry records tie devices to the user profile that mounted them and preserve last-connected times. The result, extracted from a verified image, is a device register for the machine's whole working life — including hardware nobody mentions until it appears in the schedule.

Placing named files on a named device

A connection proves presence; the case usually needs movement. Link files and jump lists record company documents being opened from the removable drive's letter, with paths and timestamps; shellbags preserve the folder structure browsed on the device, even after it has gone; and the change journal orders the surrounding file activity minute by minute. Where the stick itself is produced, its own image completes the account: the files, their timestamps, and whatever was deleted from it since.

Copy times, read correctly

File timestamps repay careful reading, and copying has a signature. When a file is copied to a new volume its creation time is set to the moment of copying while its modification time travels with the content — so a document apparently created at 23:41, yet last modified two years earlier, is telling you when it was copied, not when it was written. Set against the device register and the journal, that signature dates each transfer — and out-of-hours clusters of them seldom read as routine.

Cards, portable SSDs and everything between

The same discipline covers more than sticks. SD and microSD cards from cameras, dashcams and drones, CF cards from older kit, and portable SSDs all pass through identical imaging and analysis — and as memory card forensics experts we recover deleted photographs and video from the cards themselves as readily as we trace documents onto them. Where a card is the whole case, both the card and the machine that wrote to it are examined, so each account checks the other.

Method and custody live at the forensic recovery hub. Deletion dating continues on deleted-file forensics, and the employer casework this feeds sits on employee data theft. Fees are on our prices page.

// what the examination reports

The removable-media findings, itemised

Each finding is dated, attributed to an account, and tied to the artefact behind it.

Device register

Every stick, card and drive the machine has seen — maker, model, serial.

Connection chronology

First and last appearances of each device, dated to the second.

Opened-from traces

Documents opened from the device's letter, with paths and times.

Browsed folders

The directory structure explored on the device, preserved in shellbags.

Copy signatures

Timestamp patterns that date each transfer onto the device.

Card & SSD imaging

The media itself captured and its deleted content recovered.

// fees and footing

Forensic fees, and the lawful basis we require

What forensic work costs

The free diagnostic that opens every case is completed within 2 working days of arrival; forensic casework itself is not a no fix, no fee service. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. Both figures are itemised on our prices page, and the written scope is agreed before payment is taken.

Who we can act for

Removable-media casework proceeds on company machines and company-issued media, or under a solicitor's instruction. Instructions are accepted on three footings only: equipment the company itself owns; the instruction of a solicitor, insurer or court; or devices that are genuinely the client's own — including jointly owned machines in matrimonial matters. We do not hack, we do not intercept live communications, and we do not examine a device the instructing client has no right to examine.

// getting your device to us

Sending it in — easier than you'd think

Sticks, cards and the machines that wrote to them are strongest examined together. Call 0800 689 0668 to agree the set; each item is signed for at our Leeds location and entered into the custody record on arrival.

Is the drive still inside a computer, laptop, MacBook, iMac, CCTV / DVR or server? Take the hard drive or SSD out first and post the bare drive on its own — removing drives from machines isn't a service we offer. Storage that's soldered to a motherboard (Apple Silicon Macs, certain slim laptops) is the one thing we can't work on: if it doesn't come out, it can't come in.

  • Bubble wrap and a sturdy box or padded envelope will do nicely — cables, caddies and power bricks can stay at home.
  • Print off the booking-in & shipping form (PDF), add your name, number and a line or two on what happened, and tuck it in the parcel.
  • Royal Mail Special Delivery keeps it tracked and insured the whole way; your own courier does the same job if you'd sooner book one. There's no collection service at this end.
  • Happier handing it over in person? Reception at the address here takes drop-offs, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Leeds Data Recovery

17th Floor, The Pinnacle
Albion Street
Leeds, LS1 5AA

↓ Print the booking-in & shipping form (PDF)

Address the parcel for the attention of Leeds Data Recovery — about 40 minutes from York via the A64 and A1(M), or next working day by tracked post. You'll hear from us the moment it's booked onto the bench.

Not certain what to pack? Ring 0800 689 0668 first, or run the free online diagnostic.

// removable media — answered before instruction

Asked whenever a stick is involved

The machine alone goes a long way: the device register, connection times, opened-from traces and copy-signature timestamps all live on the computer. What the stick adds is confirmation of content. We state plainly which conclusions the machine supports by itself and which strengthen if the device is later produced or disclosed.
Yes. Its image shows the files as they stand, their copy-dated timestamps, and what has been deleted from it since — including attempts to tidy it before hand-back. It also lets the stick's contents be matched by hash against your originals.
The register ties a serial to a machine, a user profile and connection times. Tying the hand to the keyboard at those moments is for the wider case — HR records, access logs, statements. The report is explicit about where the technical evidence stops.
Not without their consent, a solicitor-agreed protocol or a court's direction; personal property stays outside an employer's reach. The company machine's records of that stick, however, are the company's own — and they usually carry most of the story.

One serial number can carry a case.

Preserve the machine, keep the stick if you have it, and ring the freephone.