Workstation Deep Imaging

A returned laptop has one forensic moment, and it falls between hand-back and rebuild. Captured in that window — read through a write-blocker, into E01 evidence files, checked by SHA-256 — it will keep answering questions for years. Put back into service, it answers fewer with every passing week. For employers in Norfolk the rule is simple enough: the questions will keep, the image will not.

Scope first, then work. The free diagnostic comes at the start and the written scope follows it; forensic fees are paid in full before an examination begins. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// machines that belong on the list

When to capture before anything else happens

One of these is enough to put a machine on the list, well ahead of the rebuild queue.

A leaver's laptop is sitting with IT, waiting to be handed on
A machine caught up in a dispute is down for rebuild or disposal
A BitLocker or FileVault device is left behind and its user has gone
Deleted material or chat history might be wanted at some stage
Browsing, VPN or remote-access activity has come into question
A drive is suspected of having been wiped deliberately

Capture now, hand the laptop on afterwards

The arithmetic is lopsided. Taking an image today — the disk read behind a write-blocker into E01 evidence files and checked by SHA-256 — costs a fraction of what that same evidence is worth once there is a dispute to spend it on, and the hardware goes back into service afterwards, because the evidence no longer depends on it. Leave the image untaken, hand the laptop on, and each day of a new user's work sits over the top of the last user's traces. Firms that capture leavers' machines as a habit are never left explaining a hole.

What a full capture holds on to

Considerably more than the documents. Browsing history, cache and cookies put research and uploads back together. Drafts and copies nobody ever deliberately saved sit in the temporary files. Pieces of whatever was in memory — a document left open, a chat window, now and again a credential — survive in the pagefile and the hibernation file. Slack and Teams keep local caches that give back conversations since deleted out of the apps. Which networks the machine was on, and at what hour, comes from the VPN and connection logs. A rebuild takes all of it away; a capture keeps it.

Locked machines, taken in good time

Encryption repays early attention. Where a device is protected by BitLocker or FileVault it should be imaged while its keys are still in escrow and its passwords still known — ahead of the leaver's account being closed, the directory being tidied, or a rebuild clearing the TPM. On a Windows volume that is live and unlocked there is a second route: Volume Shadow Copies pulled from the running system, which step around the encryption question because the volume is open while you are holding it. Encrypted-volume work is Forensic-classed and, as with everything on this page, payable upfront once the scope is agreed.

Wiped, or reported to have been

A claim of wiping is tested rather than accepted. Erase utilities and boot tools — DBAN among them — leave evidence of their own: boot records, signatures belonging to the tool, the pattern an overwrite leaves behind, and timing that can be pinned against everything else going on that week. Runs that were interrupted or only partial happen often and leave whole regions recoverable, and a hardware erase command can be read against the drive's own logs. Where the wipe really did finish, the report says so and gives the date, since wiping a drive deliberately as proceedings approach is a finding all by itself.

Custody and verification are described at the forensic recovery hub. What removal evidence looks like on a copy belongs to deleted-file forensics, and the duty to preserve to legal hold and chain of custody. Costs are on the prices page.

// what one capture holds

Still useful two years later

Taken once, verified, and there for whatever the dispute asks afterwards.

E01 evidence files

The disk entire, in the container other examiners can open and check.

Hash values

SHA-256 showing the image, and every copy taken from it, unaltered.

Browser traces

History, cache and cookies rebuilding research and uploads.

Memory leftovers

Pagefile and hibernation contents: documents, chats, credentials.

Chat caches

Local Slack and Teams stores, deleted conversations brought back.

Connection logs

VPN and network traces putting the machine on networks at set hours.

// what it costs, and who we can act for

Forensic fees and the footing we work on

The fees, plainly

Each instruction opens with the free diagnostic, which takes 2 working days from the day a device reaches the bench. Forensic casework itself falls outside no fix, no fee. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. BitLocker and other encrypted-volume work is Forensic-classed and payable upfront on the same terms. Both figures also appear on the prices page, and no money is taken until a written scope has been agreed.

The footing we need

Imaging runs on company-owned machines, on hardware of your own, or under a solicitor's instruction. Three footings open the door and there is no fourth: kit the company itself owns; a written instruction from solicitors, an insurer or the court; or a device that is genuinely the client's, which in a family matter means their own machine or one owned jointly. We do not hack. Live communications are not intercepted. Where a client has no right to look inside a device, neither have we.

// getting your device to us

Getting it here — no great performance

Tell us the machine count and where you stand on encryption when you call 0800 689 0668, and the capture is scoped in writing. Collection is not offered: drives come by tracked, insured post or over the counter at our Cambridge location, and custody is logged at the signature.

Is the drive still bolted inside a laptop, desktop, MacBook, iMac, server or CCTV / DVR recorder? The hard drive or SSD needs to come out first, and only the bare drive travels — taking drives out of machines is not something we do here. Storage soldered to a motherboard (Apple Silicon Macs, one or two very thin laptops) is the single thing beyond us: if it will not come out, it cannot come in.

  • Bubble wrap and a firm box or padded envelope, packed so nothing shifts about. Cables, caddies and power bricks are no use to us — keep them.
  • Print the shipping & booking-in form (PDF), write your name, your number and a couple of lines on what happened, and put it in with the drive.
  • Royal Mail Special Delivery covers it tracked and insured door to door; a courier of your own does the same job if that suits you better.
  • Rather hand it over yourself? Reception at the address below takes drop-offs, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Cambridge Data Recovery

Compass House, Vision Park
Chivers Way
Cambridge, CB24 9AD

↓ Print the shipping & booking-in form (PDF)

Mark the parcel for the attention of Cambridge Data Recovery. From Norwich it is about an hour and twenty down the A11, then two minutes off the A14 at Junction 32 — or next working day by tracked post. You hear from us as soon as it is booked onto the bench.

Unsure what to put in the box? Ring 0800 689 0668 before you seal it, or run the free online diagnostic.

// workstation imaging — asked before instruction

What IT teams check first

Usually, which is rather why capture happens before hand-on. The verified copy becomes the evidence and the hardware goes back to being a laptop. The exception is a live dispute in which the device itself may have to be produced; there your solicitor decides, and we hold it sealed.
Weakened, not ruined. That session moved some dates and the report will say as much, but the registry, the journals, the caches and unallocated space are not undone by somebody having a look round. Note down what was done and when, stop there, and take the image.
Leave the directory as it is. The recovery key is usually still held in Azure AD, Intune or the Microsoft account attached to the machine, and the order of things is to take the image first and do the unlocking against the copy. Do it before accounts close and passwords are cycled. It is Forensic-classed work, scoped once the free diagnostic is done, and payable upfront.
Test the claim. A good number of advertised wipes turn out to have been partial, interrupted or set up wrongly, leaving regions that can be recovered, and the wipe itself can be named, dated and attributed — worth more in litigation than the files, on occasion. A wipe that genuinely finished is reported as one.

Rebuild it next week. Image it first.

One capture holds every answer the machine has left in it — ring the freephone.