USB device history
Which removable devices were connected, when, and often what was copied — recorded in the registry and system logs regardless of whether the files remain.
They use overlapping equipment and produce very different things. If findings might be tested — a tribunal, a court, a disciplinary hearing, an insurance claim — that difference decides whether you have evidence or an assertion.
Technically the two overlap almost entirely. What separates them is that nothing may write to the original, everything is hashed so alteration would be demonstrable, and each step is logged well enough to repeat months later.
The technical basis for the claim that nothing was altered.
Physical hardware between the evidence drive and the workstation that passes read commands through and refuses write commands at the interface level. Not a software setting that could be misconfigured — the drive cannot be written to even by accident.
A SHA-256 hash is computed across the source during imaging and again across the resulting image. Matching values demonstrate the copy is bit-identical. Change a single bit and the hash changes completely, so any later alteration is detectable.
The hash is recalculated whenever the image is used. If it still matches the acquisition value, the working copy is provably unchanged since it was taken.
Tools, versions, parameters, timestamps and findings recorded as the work proceeds — so an independent examiner can repeat the process and reach the same result.
The administrative half, and the half that fails most often.
Chain of custody is a documented, unbroken record of who had the item from seizure to report: a signed exhibit record on receipt describing what arrived and in what condition, sealed storage with restricted access, and a logged entry for every movement or handling event.
It matters because the technical work can be flawless and still be undermined by a gap. If there is a period where nobody can say where the drive was or who could reach it, the opposing position is straightforward — and it is an argument about paperwork rather than about the findings.
In the UK this follows ACPO principles for digital evidence, which in practice mean: do not change the original; if you must, be competent to do so and explain why; keep a record another examiner could follow; and the person in charge is responsible for compliance.
Windows and macOS record activity extensively, and much survives deletion of the files themselves.
Which removable devices were connected, when, and often what was copied — recorded in the registry and system logs regardless of whether the files remain.
Link files, jump lists and shellbags record what was opened and which folders were browsed, including material since deleted.
Recovered from unallocated space with original creation and modification times intact, which is frequently what matters more than the content.
File system, registry and log timestamps combined into an ordered account of what happened and when.
And it is the one most often ignored, usually with good intentions.
Do not examine it first. Booting the machine changes timestamps across hundreds of files, may trigger updates, and can start writing before anyone has looked. Opening a document to check whether it is the right one alters its last-accessed time. Copying files off with a file manager creates no record of what was there.
If there is any prospect the material becomes evidence, preserve it exactly as it is and say so at the first call — it changes handling from the moment it arrives. Where a routine recovery later turns out to involve a dispute or a data breach, having imaged it properly at the outset costs nothing and keeps every option open.
Forensic work is from £800 +VAT after scoping, with a 50% deposit, and it sits outside no fix, no fee — because establishing that nothing improper occurred is a legitimate result and takes the same examination as establishing that it did.
Recovery returns your files. Forensic work additionally proves nothing changed — write-blocked acquisition, SHA-256 hashing showing the copy is bit-identical, and a documented chain of custody following ACPO principles.
Hardware placed between the evidence drive and the workstation that passes read commands through and refuses writes at the interface level. Because it is physical rather than a software setting, the source cannot be altered even by accident.
A SHA-256 hash computed at acquisition and re-verified later demonstrates the working copy is bit-identical to the source. Changing a single bit changes the hash completely, so any alteration after acquisition is detectable.
An unbroken documented record of who held the item and when, from receipt to report. The technical work can be flawless and still be undermined by a gap where nobody can say where the drive was or who could reach it.
Often. USB device records, link files, jump lists, shellbags and file system timestamps combine to show what was attached and accessed and when — frequently including material that has since been deleted.
No, and this is where most evidence is compromised. Booting changes timestamps across hundreds of files and may trigger writes; opening a document alters its access time. Preserve it exactly as it is and say so when you call.