Service — Digital Forensics

The evidence is often in the data.

Specialist digital forensic capability — preserving, recovering and analysing digital evidence to a standard that holds up in scrutiny and in court.

What we recover & analyse

Where the evidence lives.

Forensic workstation with multiple screens of data analysis and a write-blocker device in a dim, blue-lit room
A laptop and desktop computer on a dark desk

Computers and laptops

Windows and macOS machines. Internal drives, user profiles, installed software, file and browsing activity, and what was connected to the machine and when.
A smartphone and tablet on a dark surface

Mobile phones and tablets

iOS and Android. Messages, call logs, contacts, app data, and photographs with their embedded timestamps and location data.
External drives, USB media and memory cards

Data storage

External drives, USB media, memory cards, network attached storage, and business servers.
A data centre server aisle

Cloud accounts

Email, file sync services such as OneDrive, Google Drive and Dropbox, and collaboration platforms.
A disassembled hard drive in a data recovery lab

Deleted and lost material

Recovery of deleted files, emails and messages, earlier versions of documents, and fragments left behind in unallocated space.
A stack of printed documents and folders

Documents and their metadata

When a document was created, modified and last opened, what produced it, who authored it, and whether that history has been altered.
Financial statements and accounting ledgers

Financial and transactional records

Statements, ledgers, accounting exports and system logs, read together so a transaction can be placed in context.
Method

How we work.

01

Preserve before anything else

We take a forensic image first and work only from copies. The original is never altered, because a single careless step can put the whole body of evidence in question.

02

You don't choose what we look at

We image and then filter, rather than asking you to send us the documents you think matter. That is what keeps our findings independent, and it is the first thing opposing counsel will test.

03

Chain of custody, written down

Every item is hashed when we receive it and that hash is recorded. Anyone can later confirm that what we examined is what we were given, unchanged.

04

Filter to what is relevant

A terabyte of data is rarely the job. We narrow to the accounts, date ranges and material that bear on the question, and we record what we excluded and why.

05

Test assertions against primary sources

An analysis is not evidence of itself. Every assertion is matched back to an original document, and where no document supports it, we say so.

06

Report what we did not find

Findings that are unsupported or contradicted go in the report alongside the ones that help. A report that only contains good news is worth very little when it is challenged.

Deliverables

What you receive.

A forensic report

Method, findings, and the limits of those findings, written so a non-technical reader can follow it.

An opinion that can go before a court

Expressed by the person who formed it, and prepared to be tested.

A statement or affidavit

Where proceedings require it.

The preserved evidence and its hashes

So another expert can examine the same material and check our work.

A plain briefing

For you, or for your solicitor, on what the material does and does not establish.

Honest limits

What metadata can and cannot prove.

What it can establish

When a document was created, changed or last opened; what software or device produced it; whether a creation date has been altered; whether a file genuinely predates the event someone says it followed; and the revision and authorship trail behind a document.

What it cannot

What happened away from the keyboard. Metadata may show a document was back-dated. It will not tell you who was in the room, what was said, or who directed it. So we pair it with witness material and primary documents, and we set out in the report where the data stops and inference would begin.

We say this plainly because a forensic opinion that reaches further than the data supports does not survive cross-examination — and it takes the rest of the case with it.

The people

Who does the work.

The work is led by Daniel Baulch, a former detective with Victoria Police whose career was spent in organised crime and anti-corruption investigation. Digital evidence is assessed by someone who has had to put evidence before a court and defend it.

The forensic examination is led by Bobby Pabala, Lead Director of Digital Forensics, whose background spans serious fraud investigation, anti-corruption work and covert operations across Australia, New Zealand and the Pacific.

Need digital evidence preserved or analysed?