Digital evidence
Computer, Email & Cloud Forensics
Reconstruct activity across endpoints, mail systems and cloud platforms without losing the context that makes an artifact meaningful.
The engagement
One activity, several systems
Modern matters cross systems. A document may begin on a workstation, move through a collaboration platform, be attached to an email, synchronize to personal storage and disappear from one location while remaining in another.
GDF develops a source map before collection, preserves evidence proportionately and builds timelines from corroborating artifacts. That approach is designed for disputes and internal examinations where provenance, authorship, access, deletion or intent is contested.
Scope
Workstation and server forensics
Forensic imaging and artifact analysis across supported Windows, macOS and server environments.
Email authentication
Header, mailbox, server and account analysis for disputed messages, attachments and delivery paths.
Cloud collaboration
Preservation and review of supported Microsoft 365, Google Workspace and collaboration-platform records.
File provenance and activity
Creation, modification, access, transfer and deletion artifacts considered as a correlated record.
User and account activity
Logon, credential, browser, USB, network and application records assessed against the matter timeline.
Timeline reconstruction
Normalization of timestamps and events from multiple sources, with timezone and clock limitations stated.
Methodology
How the examination works
-
Map
Identify custodians, systems, accounts, retention windows and the questions each source may answer.
-
Acquire
Collect with hash verification and a record of source, method, date, operator and exceptions.
-
Reconstruct
Correlate file, email, account and cloud events rather than relying on a single artifact.
-
Report
Explain findings, alternative interpretations and unavailable evidence in plain language.
Evidence commonly examined
Evidence reviewed
- Laptops, desktops and servers
- Mailboxes, message headers and journals
- Cloud audit and collaboration records
- File-system and operating-system artifacts
- Browser, USB and application history
- Backups, snapshots and archives
What you can expect
What you receive
- Evidence-source and preservation map
- Correlated event timeline
- Authenticated message or file analysis
- Examiner report, exhibits and testimony support
Frequently asked
Common questions
Can you determine whether an email is genuine?
Often we can assess consistency across headers, mailbox records, server logs and related account activity. The conclusion depends on which original records remain available.
Do you need the original computer?
Not always, but an original device or forensic image may contain artifacts absent from a copied file or mailbox export. We scope the least disruptive collection that can answer the question.
Can you examine Microsoft 365 or Google Workspace?
Yes, where authorized access and retained audit data are available. Cloud retention windows can be short, so early preservation matters.
Related capabilities
Related services
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189