Workstation Deep Imaging

A leaver's laptop has one forensic moment: the interval between hand-back and reissue. Imaged then — write-blocked, into E01 evidence files, verified by SHA-256 — it can answer questions for years. Reused, it answers fewer every day. For York employers the rule is simple: the questions can wait; the image cannot.

Method before speed. The free assessment and a written scope come first; forensic fees are settled in full before any examination starts. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// machines that should be imaged now

When a workstation needs capturing

Any of these puts a machine on the imaging list before it goes anywhere near the rebuild queue.

A leaver's laptop is sitting with IT, queued for reissue
A machine involved in a dispute is scheduled for rebuild or disposal
A BitLocker or FileVault device remains, but its user has gone
Deleted material or messaging history may be needed later
Browsing, VPN or remote-access activity is in question
A drive is suspected of having been deliberately wiped

Image before reissue, every time

The economics are lopsided. A forensic image taken now — the full disk captured behind a write-blocker into E01 evidence files, verified by SHA-256 — costs a fraction of what the same evidence is worth once a dispute is live, and the machine can go back into service the day after, because the evidence now exists independently of it. Skip the image, reissue the laptop, and every day of the new user's work overwrites the old user's traces. Businesses that image leavers' machines as routine never have to explain a gap.

What a full image preserves

Far more than documents. Browser history, cache and cookies reconstruct research and uploads; temporary files hold drafts and copies that were never saved anywhere else; the pagefile and hibernation file carry fragments of whatever was in memory — open documents, chat windows, even credentials; Slack and Teams keep local caches from which conversations are recovered after they have been deleted from the apps; and VPN and connection logs place the machine on networks at times that matter. None of this survives a rebuild. All of it survives an image.

Encrypted machines, taken in time

Encryption rewards early capture. A BitLocker or FileVault machine is imaged while the keys are still escrowed and the passwords still known — before the leaver's account is closed, the directory tidied, or the TPM cleared by a rebuild. On a live, unlocked Windows volume there is a further route: Volume Shadow Copies captured from the running system, which sidestep the encryption question entirely because the volume is open while you hold it. Encrypted-volume work is Forensic-classed and, like everything on this page, payable upfront once scoped.

Wiped, or said to be

Claims of wiping are tested, not taken. Secure-erase and boot-disk tools such as DBAN leave their own evidence — boot records, tool signatures, characteristic overwrite patterns, and timing that can be fixed against the surrounding events. Interrupted and partial runs are common, leaving whole regions recoverable; hardware secure-erase commands are checked against the drive's own records. Where a wipe genuinely completed, the report says so plainly — and dates it, because a deliberate wipe on the eve of proceedings is itself a finding.

The custody and verification discipline is at the forensic recovery hub. What deletion evidence looks like on the image is covered by deleted-file forensics; preservation duties by legal hold & chain of custody; fees by our prices page.

// preserved in every deep image

What the capture holds for later

Taken once, verified, and available to every question the dispute produces afterwards.

E01 evidence files

The full disk in the container the forensic profession exchanges.

Hash verification

SHA-256 values proving the image, and every copy of it, unchanged.

Browser artefacts

History, cache and cookies reconstructing research and uploads.

Memory-file fragments

Pagefile and hibernation content: documents, chats, credentials.

Chat caches

Slack and Teams local stores, with deleted conversations recovered.

Connection records

VPN and network traces placing the machine at times and places.

// fees and footing

Forensic fees, and the lawful basis we require

What forensic work costs

The free diagnostic that opens every case is completed within 2 working days of arrival; forensic casework itself is not a no fix, no fee service. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. BitLocker and other encrypted-volume work is Forensic-classed and payable upfront on the same terms. Both figures are itemised on our prices page, and the written scope is agreed before payment is taken.

Who we can act for

Imaging proceeds on company-owned machines, your own hardware, or a solicitor's instruction. Instructions are accepted on three footings only: equipment the company itself owns; the instruction of a solicitor, insurer or court; or devices that are genuinely the client's own — including jointly owned machines in matrimonial matters. We do not hack, we do not intercept live communications, and we do not examine a device the instructing client has no right to examine.

// getting your device to us

Sending it in — easier than you'd think

Give us the machine count and the encryption position when you call 0800 689 0668; imaging is then scoped in writing the same day. Devices travel tracked next-day or by hand to our Leeds location, and custody is recorded at the signature.

Is the drive still inside a computer, laptop, MacBook, iMac, CCTV / DVR or server? Take the hard drive or SSD out first and post the bare drive on its own — removing drives from machines isn't a service we offer. Storage that's soldered to a motherboard (Apple Silicon Macs, certain slim laptops) is the one thing we can't work on: if it doesn't come out, it can't come in.

  • Bubble wrap and a sturdy box or padded envelope will do nicely — cables, caddies and power bricks can stay at home.
  • Print off the booking-in & shipping form (PDF), add your name, number and a line or two on what happened, and tuck it in the parcel.
  • Royal Mail Special Delivery keeps it tracked and insured the whole way; your own courier does the same job if you'd sooner book one. There's no collection service at this end.
  • Happier handing it over in person? Reception at the address here takes drop-offs, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Leeds Data Recovery

17th Floor, The Pinnacle
Albion Street
Leeds, LS1 5AA

↓ Print the booking-in & shipping form (PDF)

Address the parcel for the attention of Leeds Data Recovery — about 40 minutes from York via the A64 and A1(M), or next working day by tracked post. You'll hear from us the moment it's booked onto the bench.

Not certain what to pack? Ring 0800 689 0668 first, or run the free online diagnostic.

// workstation imaging — answered before instruction

Asked before the rebuild queue moves

Usually — that is the point of imaging before reissue. The verified image becomes the evidence; the hardware becomes a laptop again. The exception is a live dispute where the device itself may need producing, in which case your solicitor decides and we store it sealed.
Weakened, not ruined. Their session re-dated some artefacts, and the report will account for that honestly — but registries, journals, caches and unallocated space do not vanish because somebody browsed. Note what was done and when, stop now, and image.
Do not tidy the directory. Recovery keys usually wait in Azure AD, Intune or the associated Microsoft account; we image first and unlock against the copy. Move before accounts are closed and passwords rotated — and treat it as Forensic-classed work, scoped after the free assessment and payable upfront.
Test the claim. Many advertised wipes were partial, interrupted or misconfigured, leaving recoverable regions — and the wipe itself can be identified, dated and attributed, which in litigation is sometimes worth more than the files. A genuinely completed overwrite is reported as exactly that.

Rebuild the laptop next week. Image it today.

One capture preserves every answer the machine will ever give — ring the freephone.