When copying is suspected, the useful questions are narrow: which device, connected when, carrying which files. Windows keeps most of the answers without being asked. We read them from a verified image and set them out in order — for employers from Clifton Moor to the distribution estates along the A64.
◇ Method before speed. The free assessment and a written scope come first; forensic fees are settled in full before any examination starts. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.
A stick, a card or a portable drive sits at the centre of more disputes than any other exhibit.
Windows records each removable device it meets. The USBSTOR registry key holds the maker, model and serial number of every stick, card reader and portable drive connected to the machine; setupapi.dev.log dates each device's first appearance to the second; further registry records tie devices to the user profile that mounted them and preserve last-connected times. The result, extracted from a verified image, is a device register for the machine's whole working life — including hardware nobody mentions until it appears in the schedule.
A connection proves presence; the case usually needs movement. Link files and jump lists record company documents being opened from the removable drive's letter, with paths and timestamps; shellbags preserve the folder structure browsed on the device, even after it has gone; and the change journal orders the surrounding file activity minute by minute. Where the stick itself is produced, its own image completes the account: the files, their timestamps, and whatever was deleted from it since.
File timestamps repay careful reading, and copying has a signature. When a file is copied to a new volume its creation time is set to the moment of copying while its modification time travels with the content — so a document apparently created at 23:41, yet last modified two years earlier, is telling you when it was copied, not when it was written. Set against the device register and the journal, that signature dates each transfer — and out-of-hours clusters of them seldom read as routine.
The same discipline covers more than sticks. SD and microSD cards from cameras, dashcams and drones, CF cards from older kit, and portable SSDs all pass through identical imaging and analysis — and as memory card forensics experts we recover deleted photographs and video from the cards themselves as readily as we trace documents onto them. Where a card is the whole case, both the card and the machine that wrote to it are examined, so each account checks the other.
Method and custody live at the forensic recovery hub. Deletion dating continues on deleted-file forensics, and the employer casework this feeds sits on employee data theft. Fees are on our prices page.
Each finding is dated, attributed to an account, and tied to the artefact behind it.
Every stick, card and drive the machine has seen — maker, model, serial.
First and last appearances of each device, dated to the second.
Documents opened from the device's letter, with paths and times.
The directory structure explored on the device, preserved in shellbags.
Timestamp patterns that date each transfer onto the device.
The media itself captured and its deleted content recovered.
The free diagnostic that opens every case is completed within 2 working days of arrival; forensic casework itself is not a no fix, no fee service. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. Both figures are itemised on our prices page, and the written scope is agreed before payment is taken.
Removable-media casework proceeds on company machines and company-issued media, or under a solicitor's instruction. Instructions are accepted on three footings only: equipment the company itself owns; the instruction of a solicitor, insurer or court; or devices that are genuinely the client's own — including jointly owned machines in matrimonial matters. We do not hack, we do not intercept live communications, and we do not examine a device the instructing client has no right to examine.
Sticks, cards and the machines that wrote to them are strongest examined together. Call 0800 689 0668 to agree the set; each item is signed for at our Leeds location and entered into the custody record on arrival.
Is the drive still inside a computer, laptop, MacBook, iMac, CCTV / DVR or server? Take the hard drive or SSD out first and post the bare drive on its own — removing drives from machines isn't a service we offer. Storage that's soldered to a motherboard (Apple Silicon Macs, certain slim laptops) is the one thing we can't work on: if it doesn't come out, it can't come in.
↓ Print the booking-in & shipping form (PDF)
Address the parcel for the attention of Leeds Data Recovery — about 40 minutes from York via the A64 and A1(M), or next working day by tracked post. You'll hear from us the moment it's booked onto the bench.
Not certain what to pack? Ring 0800 689 0668 first, or run the free online diagnostic.
Preserve the machine, keep the stick if you have it, and ring the freephone.