Digital evidence

Computer, Email & Cloud Forensics

Reconstruct activity across endpoints, mail systems and cloud platforms without losing the context that makes an artifact meaningful.

Bagged hard drive beside a forensic write blocker.

The engagement

One activity, several systems

Modern matters cross systems. A document may begin on a workstation, move through a collaboration platform, be attached to an email, synchronize to personal storage and disappear from one location while remaining in another.

GDF develops a source map before collection, preserves evidence proportionately and builds timelines from corroborating artifacts. That approach is designed for disputes and internal examinations where provenance, authorship, access, deletion or intent is contested.

Scope

  • Workstation and server forensics

    Forensic imaging and artifact analysis across supported Windows, macOS and server environments.

  • Email authentication

    Header, mailbox, server and account analysis for disputed messages, attachments and delivery paths.

  • Cloud collaboration

    Preservation and review of supported Microsoft 365, Google Workspace and collaboration-platform records.

  • File provenance and activity

    Creation, modification, access, transfer and deletion artifacts considered as a correlated record.

  • User and account activity

    Logon, credential, browser, USB, network and application records assessed against the matter timeline.

  • Timeline reconstruction

    Normalization of timestamps and events from multiple sources, with timezone and clock limitations stated.

Methodology

How the examination works

  1. Map

    Identify custodians, systems, accounts, retention windows and the questions each source may answer.

  2. Acquire

    Collect with hash verification and a record of source, method, date, operator and exceptions.

  3. Reconstruct

    Correlate file, email, account and cloud events rather than relying on a single artifact.

  4. Report

    Explain findings, alternative interpretations and unavailable evidence in plain language.

Evidence commonly examined

Evidence reviewed

  • Laptops, desktops and servers
  • Mailboxes, message headers and journals
  • Cloud audit and collaboration records
  • File-system and operating-system artifacts
  • Browser, USB and application history
  • Backups, snapshots and archives

What you can expect

What you receive

  • Evidence-source and preservation map
  • Correlated event timeline
  • Authenticated message or file analysis
  • Examiner report, exhibits and testimony support

Frequently asked

Common questions

Can you determine whether an email is genuine?

Often we can assess consistency across headers, mailbox records, server logs and related account activity. The conclusion depends on which original records remain available.

Do you need the original computer?

Not always, but an original device or forensic image may contain artifacts absent from a copied file or mailbox export. We scope the least disruptive collection that can answer the question.

Can you examine Microsoft 365 or Google Workspace?

Yes, where authorized access and retained audit data are available. Cloud retention windows can be short, so early preservation matters.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.