Clear digital evidence for attorneys and businesses
Computer, Email & Cloud Forensics
Can GDF collect and analyze evidence from computers, email and cloud accounts? Yes. We preserve the evidence, reconstruct activity and explain the findings in clear reports that help counsel and business leaders act.
The engagement
Connect the evidence to the questions in your case
A disputed email. A departing employee. A shared folder containing proprietary documents. GDF connects evidence across computers, messages and cloud accounts to answer the questions driving your matter: who accessed information, where it went and what happened next.
Our computer, email and cloud forensic services bring preservation, technical analysis, eDiscovery and expert testimony together. We work with attorneys, business owners and security teams to define the questions, identify the relevant sources and deliver a clear account of the findings.
For example, a document may be edited on a laptop, synchronized to OneDrive, attached to an email and shared with another account. Examining the computer alongside the email and cloud logs connects those events into a timeline. The report identifies the supporting records so counsel can follow the activity and use the findings in the case.
Remote collection makes evidence gathering convenient for clients and distributed teams. We coordinate access and collection with the account holder or authorized administrator. Email users can continue using their accounts during collection, and we arrange the computer or mobile collection process around the devices and evidence your case needs.
Start with the question you need answered, the people and accounts involved, and your deadline. We will help you choose the collection and analysis scope, explain the deliverables and discuss the cost.
Scope
Computer forensics and activity timelines
We examine laptops, desktops, servers and forensic images for file activity, browser history, USB connections, sign-ins and application records. File creation, modification, copying and deletion artifacts help reconstruct the sequence of events around the dates that matter.
Email authentication, tracking and relationships
We analyze messages, headers, attachments, mailbox records and email logs to establish authenticity and trace communication. Sender, recipient and timing information can build relationship maps showing how people and accounts communicated.
Cloud files, sharing and account access
Microsoft 365, Google Workspace, Box and Dropbox can hold documents, file versions, sharing activity and account logs. We correlate these records with computer and email evidence to explain access, movement and use of information. Explore cloud and SaaS forensic analysis.
Compromised email accounts
Our business email takeover forensic service examines phishing messages, sign-in activity, forwarding rules and related evidence to establish the entry path, data access and attacker persistence.
Mobile messages and chats
Connect the computer and account timeline with texts and app conversations through mobile-device forensics. Remote collection lets clients retain their phones and simplifies coordination for counsel.
eDiscovery and expert support
Move from preserved evidence to focused review, production and clear expert findings. GDF coordinates collection and analysis with your discovery requirements, reporting needs and case deadlines.
Email and files: Microsoft 365 and Google Workspace
GDF forensically collects Outlook, Gmail and email archives together with relevant documents and activity logs. Preserving email and logs early keeps the original messages, attachments and account activity together for analysis.
- Microsoft 365 and Outlook email forensics: email authentication, tracking, OneDrive and SharePoint collection, and Microsoft 365 log analysis.
- Google Workspace and Gmail forensics: Gmail messages, Google Drive files, sharing records and Workspace logs.
- Business email takeover forensics: hacked mailboxes, phishing, account access and attacker persistence.
Professional collection preserves the original evidence and its handling history from the start. GDF coordinates remote access so users can keep working while their email is collected.
Did someone leave with company information?
GDF Core Analysis is a flat-rate forensic service for the agreed scope. We preserve the former employee's or business associate's email, documents and computer evidence, then create a clear timeline of activity around the departure. The examination can include chat histories, available AI-use records and cloud storage activity.
- Employee exit Core Analysis: understand file copying, communication and sharing before an employee leaves.
- Executive departure Core Analysis: examine sensitive business information and activity around an executive's exit.
- Business partner separation Core Analysis: clarify access to company records and information movement during a separation.
The report gives counsel and business leaders an understandable view of the activity, with the evidence supporting each finding.
From digital evidence to discovery and testimony
Need help with an eDiscovery stipulation, keyword list or discovery demand? GDF helps counsel define relevant sources, focus collection and organize data for review and production. Our internal tools support collection, deduplication, standard system-file filtering, review and load-file preparation. Focused workflows and cost-effective hosting help small and midsize businesses manage discovery within their resources.
Explore eDiscovery collection, processing and production or Get a free consultation.
When the findings need an expert explanation, GDF prepares reports, affidavits, declarations and exhibits, and provides deposition and trial testimony. We connect the technical evidence to the questions judges and juries need to understand.
For a published example, read COMLAB v. Kal Tire, which describes GDF's examination of email and document evidence and the court's findings concerning the expert testimony. Explore expert witness services and meet our forensic experts.
Methodology
From preservation to a clear explanation
-
Define the questions
Discuss the matter, people, devices, accounts and deadlines. Agree on the evidence sources, collection approach and deliverables.
-
Preserve the evidence
Collect original data and relevant logs using documented forensic procedures, integrity checks and chain-of-custody records.
-
Connect the activity
Correlate files, messages, sign-ins and sharing events. Align timestamps and explain the source records supporting the timeline.
-
Explain the findings
Prepare a concise report with relevant exhibits. Support counsel with discovery, affidavits, deposition and testimony as the engagement requires.
Evidence commonly examined
Evidence reviewed
- Computers, forensic images, backups and file histories
- Outlook, Gmail, email archives, headers and attachments
- OneDrive, SharePoint, Google Drive, Box and Dropbox records
- Sign-in, sharing and email activity logs
- Browser, USB, chat and available AI-use records
- Mobile messages and app conversations
What you can expect
What you receive
- Documented collection and chain-of-custody records
- A timeline connecting computer, email and cloud activity
- Email authentication, communication maps and file analysis
- Relevant data prepared for review and agreed production formats
- Clear reports, supporting exhibits and expert testimony
Discuss your evidence and case needs
Tell us what you need to establish, which devices or accounts are involved, and your deadline. We will help define the collection, analysis and reporting plan.
Read a public-record forensic case study · Review the forensic team and relevant qualifications
Get a free consultationFrequently asked
Common questions
Can GDF collect and analyze computer, email and cloud evidence?
Yes. GDF preserves and examines computers, email accounts, cloud files and activity logs. We connect the records into a timeline and explain the findings in clear language for attorneys and business decision-makers.
Can email and cloud data be collected remotely?
Yes. We coordinate remote collection with the account holder or authorized administrator, preserve the original data and document the collection. Email users can continue using their accounts while collection takes place.
Can you tell whether an email is real or altered?
Yes. GDF conducts email authentication examinations using message headers, attachments, mailbox records, email logs and related evidence. We explain the findings and the records supporting the authentication analysis.
Can you determine whether an employee took company information?
GDF examines computer activity, email, cloud sharing, chat histories and other relevant records to establish how company information was accessed, copied or transferred. Our flat-rate Core Analysis service preserves the agreed evidence and produces an understandable activity timeline.
Can you analyze a hacked email account?
Yes. Our business email takeover forensic service examines the attack path, account activity, data access, phishing and persistence. We correlate email and sign-in logs with messages and related records to explain the compromise.
Can you help control the cost of eDiscovery?
Yes. We help counsel focus the collection, keywords and review on relevant information. Our internal tools support deduplication, filtering, review and load-file preparation, and we can design cost-effective hosting around the matter and budget.
Can you prepare a report and provide expert testimony?
Yes. GDF experts prepare reports, affidavits, declarations and exhibits, and provide deposition and trial testimony. We explain complex technology in language judges, juries and business leaders can understand.
What should I have ready for the first conversation?
Bring the question you need answered, the relevant people and organizations, the types of devices and accounts involved, and your deadline. GDF will help define the scope, explain the collection process and arrange secure evidence sharing.
Talk with an examiner
Discuss your matter and next step
Tell us the systems, evidence and deadline. We can review relevant experience, potential conflicts and the scope before engagement.
Since 1992 · 24/7 dispatch · Court-tested experts
Talk with an examiner
Discuss the matter and the next step.
Tell us what happened and what you need to find out. Speak with a GDF expert about how we can help.
24/7 hotline: 1-800-868-8189