Deleted-File Forensics and Timelines

Two things usually matter about a file that has gone: what it was, and how it went. A disk normally keeps enough to answer both. Bin records, journal entries and volume snapshots between them show what a machine held, how it was used, and at what hour — and by what method — something was taken off it. For Norfolk employers, solicitors and private clients with a removal in dispute.

Scope first, then work. The free diagnostic comes at the start and the written scope follows it; forensic fees are paid in full before an examination begins. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// the disputes that land here

When the removal is the point at issue

The work suits any matter where what went, and the hour it went, carries weight.

The bin was emptied in the days before a resignation or a claim
Records are missing from a folder and nobody will say when
Someone maintains a document was never on the machine to begin with
A clean-up or wiping utility is thought to have been run
The date of the removal counts for as much as the file does
Earlier drafts are wanted of a document that has since been overwritten

Recycle bin, or something more decided

Removal comes in grades and each leaves its own mark. Send a file to the recycle bin and a small record is created alongside it, holding the path it came from, its size, and the instant it went; that record commonly outlives the emptying of the bin. Delete permanently and the bin is skipped, but all that is surrendered is the entry in the index — the contents sit where they are until something else needs the space. Which grade applied, and when, is normally the first thing established, and it frequently says something about intention.

Events put back into order

A timeline is nothing more than recorded events arranged in sequence from sources that check each other. The $MFT carries creation, modification and access times for every file. $UsnJrnl logs the operations themselves as they occur: made, renamed, removed. $LogFile supplies fine detail around the minutes in question. Event logs supply the account that was signed in and what it opened or altered beforehand. Set against the date a file was created, the hour it disappeared answers the question worth asking: housekeeping, or timing?

Copies nobody remembered to remove

A workstation holds more than one version of its own past. Volume Shadow Copies, made for restore points and backups, keep earlier states of the disk, including files that went afterwards and drafts from before an edit. Set a snapshot beside the live volume and what disappeared between two dates shows plainly. That is often the tidiest exhibit a removal case can offer: there on the 3rd, absent on the 10th, with the journal timing the removal at the 7th.

When a wiping utility has been run

Wiping software is not a quiet visitor. Detection starts from what the tools themselves leave: installer records and prefetch entries carrying the program's name, the times it ran, the signature overwriting leaves across the disk, and the noticeable absence of traces that should be present. A wipe destroys content and creates evidence in the same pass — the utility, the hour, the account behind it, and whatever it did not reach. Runs that were partial or interrupted are common, and what survives one is recovered as usual.

The imaging and custody discipline underneath this page is set out at the forensic recovery hub. Removals involving sticks and cards continue on USB device forensics, and whole-machine capture on workstation deep imaging. Costs are on the prices page.

// where the timeline comes from

Six sources, one sequence

Every source is read against the others, and the timeline rests on where they agree.

Bin records

Original path, size and the instant of removal, outliving an emptied bin.

File-table times

Creation, modification and access times for live and deleted alike.

Journal entries

Files made, renamed and removed, taken one operation at a time.

Log corroboration

The account signed in around each removal, from the system's own logs.

Volume snapshots

Earlier states of the disk, holding what has disappeared since.

Wiping traces

Which utility ran, the hour, the account, and what it left behind.

// what it costs, and who we can act for

Forensic fees and the footing we work on

The fees, plainly

Each instruction opens with the free diagnostic, which takes 2 working days from the day a device reaches the bench. Forensic casework itself falls outside no fix, no fee. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. Both figures also appear on the prices page, and no money is taken until a written scope has been agreed.

The footing we need

Removal work runs on company machines, on devices of your own, or under a solicitor's instruction. Three footings open the door and there is no fourth: kit the company itself owns; a written instruction from solicitors, an insurer or the court; or a device that is genuinely the client's, which in a family matter means their own machine or one owned jointly. We do not hack. Live communications are not intercepted. Where a client has no right to look inside a device, neither have we.

// getting your device to us

Getting it here — no great performance

Ordinary use costs a removal case a little every day, so withdraw the machine and call 0800 689 0668. Collection is not offered: it reaches our Cambridge location by tracked, insured post or over the counter, and joins the custody file at the signature.

Is the drive still bolted inside a laptop, desktop, MacBook, iMac, server or CCTV / DVR recorder? The hard drive or SSD needs to come out first, and only the bare drive travels — taking drives out of machines is not something we do here. Storage soldered to a motherboard (Apple Silicon Macs, one or two very thin laptops) is the single thing beyond us: if it will not come out, it cannot come in.

  • Bubble wrap and a firm box or padded envelope, packed so nothing shifts about. Cables, caddies and power bricks are no use to us — keep them.
  • Print the shipping & booking-in form (PDF), write your name, your number and a couple of lines on what happened, and put it in with the drive.
  • Royal Mail Special Delivery covers it tracked and insured door to door; a courier of your own does the same job if that suits you better.
  • Rather hand it over yourself? Reception at the address below takes drop-offs, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Cambridge Data Recovery

Compass House, Vision Park
Chivers Way
Cambridge, CB24 9AD

↓ Print the shipping & booking-in form (PDF)

Mark the parcel for the attention of Cambridge Data Recovery. From Norwich it is about an hour and twenty down the A11, then two minutes off the A14 at Junction 32 — or next working day by tracked post. You hear from us as soon as it is booked onto the bench.

Unsure what to put in the box? Ring 0800 689 0668 before you seal it, or run the free online diagnostic.

// deleted files — asked before instruction

Where removal cases usually start

Often, in two separate ways. The bin's own records usually survive to show what went and at what hour, and the contents themselves sit in unallocated space until something writes over them. The earlier a machine stops being used, the more of each is still there to find.
Dating it is what a timeline exists for. Records out of the bin, entries in the journal and the event logs all carry clocks of their own, and where those agree the hour can be given with confidence. Set beside the date a file was made, and the events either side of it, the timing tends to speak for itself.
It is pinned to an account and to a session: the login that was live, the address it came from, the moment it ran. Joining that account to a particular pair of hands is a job for the wider case, and the report states plainly the point at which technical attribution runs out.
Continued use eats into unallocated space gradually, so the odds slip week by week — but journals, bin records and snapshots frequently outlast it. Take it out of service now and the free diagnostic will tell you honestly what remains.

Gone is a claim. The disk says otherwise.

Take the machine out of use, ring the freephone, and let the sequence do the talking.