Frequently Asked
Questions
Straightforward answers to the questions we’re asked most often — organised by topic, and consistent with the guidance given on each of our service pages. If your question isn’t answered here, get in touch directly.
40+
Questions Answered
8+
Topic Areas
100+
Guaranteed Outcomes
Topic
General
Digital Forensics Basics
Common questions about digital forensic examinations and our services.
What is digital forensics?
Digital forensics is the process of identifying, preserving, examining, analysing and reporting on digital evidence in a manner that is methodologically sound and legally admissible. It encompasses the examination of computers, mobile devices, video footage, digital images and other electronic data sources.
Can deleted files and messages be recovered?
In many cases, deleted files and messages can potentially be recovered through forensic examination. However, recovery depends on multiple factors including the device type, file system, time elapsed since deletion, and whether the storage area has been overwritten. No responsible forensic practitioner can guarantee recovery of specific data.
How is digital evidence preserved for legal proceedings?
Digital evidence is preserved through forensic imaging — creating a bit-for-bit copy of the original media using write-blocking technology. Hash values are generated to verify the integrity of the forensic copy. A strict chain of custody is maintained from the point of evidence intake through to reporting and, if required, court presentation.
What should a solicitor provide when engaging a forensic expert?
Clear written instructions outlining the matter, the issues in dispute, the specific questions the expert is being asked to address, the evidence to be examined, and any relevant time constraints. The more precise the instructions, the more focused and useful the expert examination and report will be.
Can CCTV footage be enhanced or authenticated?
Forensic video examination can improve the visibility of information already present in the footage, and can verify the integrity and authenticity of video recordings. It is important to distinguish between improving visibility of existing data and creating information that was not present in the original evidence — a critical distinction for forensic credibility.
Computer Forensics
Computers, Laptops
& Storage Media
Common questions about computer forensic examinations.
Can deleted files be recovered from a computer?
In many cases, deleted files can potentially be recovered through forensic examination. When a file is deleted, the data may still exist on the storage medium until that space is overwritten by new data. However, recovery depends on multiple factors including the type of storage device (HDD vs SSD), the file system in use, the time elapsed since deletion, whether the drive has been defragmented or trimmed, and the extent of subsequent use. No responsible forensic practitioner can guarantee recovery of specific deleted data.
How long does a computer forensic examination take?
The duration of a computer forensic examination depends on several factors: the volume of data to be examined, the complexity of the issues, the number of devices involved, and the scope of the instructions. A focused examination of a single device with clearly defined questions may take days, while a complex matter involving multiple devices and broad terms of reference may take several weeks. We provide estimated timeframes following an initial assessment of the evidence and instructions.
Can browser history be recovered after it has been cleared?
Forensic examination may be able to recover evidence of internet browsing activity even after a user has cleared their browser history. Multiple artefacts across the operating system, browser databases, cache files, DNS cache, and other locations may retain traces of browsing activity. The extent of recovery depends on the browser, operating system, and other technical factors.
Is the original evidence altered during a forensic examination?
No. A properly conducted forensic examination does not alter the original evidence. Before any examination begins, a forensic image (bit-for-bit copy) is created using write-blocking technology, which prevents any changes to the original media. All examination and analysis is conducted on the forensic copy. Hash values are used to verify that the original evidence remains unaltered throughout the entire process.
Can USB device activity be identified on a computer?
Forensic examination can typically identify USB devices that have been connected to a computer, including details such as the device manufacturer, serial number, volume name, and the dates and times of connection. This information is recorded by the operating system in various locations and can provide valuable evidence in cases involving data theft, unauthorised access, or the transfer of files between devices.
Mobile Forensics
Phones & Tablets
Common questions about mobile forensic examinations.
Can deleted text messages be recovered from a mobile phone?
In many cases, deleted SMS messages and messages from messaging applications can potentially be recovered through forensic examination. When messages are deleted, the data may still exist in the device’s storage or application database until that space is overwritten by new data. However, recovery depends on multiple factors including the device type, operating system version, the application used, whether the device has been subsequently used, and whether backups exist. No responsible forensic practitioner can guarantee recovery of specific deleted messages.
Can deleted WhatsApp messages be recovered?
Forensic examination may be able to recover deleted WhatsApp messages from a mobile device, depending on the circumstances. WhatsApp stores message data in a database on the device, and forensic examination can analyse this database for remnant message data. Cloud backups (iCloud or Google Drive), local device backups and the device storage itself all provide potential sources for recovery. Success depends on the device type, operating system, whether backups exist and the extent of subsequent use.
Can location information be recovered from a mobile phone?
Mobile forensic examination can recover a range of location-related data. This may include GPS coordinates stored by applications, location history retained by the operating system, Wi-Fi network connection history (which can indicate geographical location), and location data embedded in photographs as EXIF metadata. The availability and completeness of location data varies depending on the device settings, applications installed, and the relevant time period.
What information can be extracted from an iPhone?
An iPhone forensic examination can potentially recover a wide range of data including: SMS and iMessage conversations, call history and voicemails, contacts and calendar entries, photographs and videos with associated EXIF metadata, emails and attachments, application data from messaging, social media and productivity applications, GPS and location history, browsing history, notes and reminders, and device usage information. The extent of data accessible depends on the iOS version, encryption settings, passcode availability and the forensic extraction method applied.
Is the mobile device altered during a forensic examination?
A properly conducted mobile forensic examination aims to minimise any changes to the original device. Prior to examination, the device is isolated from network connectivity using a Faraday bag or shielded environment to prevent remote access or data synchronisation. Forensic extraction methods are selected to minimise interaction with the device. Where any interaction with the device is necessary, the actions taken are fully documented. The examination process and any changes made are recorded in the examiner’s notes.
Video Forensics
CCTV & Video Evidence
Common questions about video forensic examinations.
Can CCTV footage be enhanced?
Forensic video examination can improve the visibility and presentation of information that is already contained within CCTV footage. This may include adjustments to brightness, contrast, sharpness, stabilisation, and frame-by-frame presentation. It is critically important to understand, however, that forensic video processing can only reveal information that is actually present in the original footage — it cannot create, recover or invent detail that was not captured at the time of recording. Any processing applied is fully documented and the original footage is always preserved unaltered.
Can CCTV footage be authenticated?
Video forensic examination can assess the integrity and authenticity of digital video evidence. This involves examination of video metadata, codec information, file structure, recording characteristics, and analysis for signs of discontinuity, editing or manipulation. The examination can provide a forensic opinion on whether footage is consistent with continuous, unaltered recording — or whether features are present that are inconsistent with authentic original footage. The absence of detected indicators does not, however, constitute proof that footage is unaltered.
Can video manipulation be detected?
Video forensic examination can identify a range of indicators that may be consistent with manipulation or editing of digital video evidence. These may include inconsistencies in metadata, encoding parameters, timestamps, frame rates, file structure and visual artefacts. However, findings must be carefully interpreted — the presence of indicators does not always confirm deliberate manipulation, and the absence of indicators does not constitute proof that footage has not been altered. Forensic opinions are expressed with appropriate qualifications and with reference to the full evidential context.
Can multiple CCTV cameras be synchronised?
Video forensic examination can assess and, where possible, synchronise footage from multiple cameras to establish a common timeline of events. This involves analysis of timestamps, recording characteristics, environmental cues and any reference events visible across multiple cameras. It is important to note that CCTV system clocks are frequently inaccurate, and any synchronisation analysis will clearly document the methodology, the assumptions made, and the degree of confidence associated with the findings.
Can the original CCTV footage be recovered?
Whether original CCTV footage can be recovered depends on the recording system, storage medium and whether the footage has been overwritten. Many CCTV systems record continuously and overwrite older footage after a set period. If footage has been overwritten, recovery may not be possible. Where footage has been exported or converted from the original system, forensic examination can assess the export process and identify any quality or evidential issues arising from that conversion. Early preservation of evidence is always recommended.
Digital Image Forensics
Photographs & Digital Images
Common questions about digital image forensic examinations.
Can a photograph be proven to be manipulated?
Digital image forensic examination can identify a range of indicators that may be consistent with manipulation or editing of a digital image. These may include inconsistencies in EXIF metadata, JPEG compression artefacts arising from re-saving after editing, pixel-level anomalies, lighting and shadow inconsistencies, and cloning or splicing artefacts. However, the presence of indicators does not always confirm deliberate manipulation, and the absence of detected indicators does not constitute proof that an image is unaltered. Findings are expressed as forensic opinions with appropriate qualifications and reference to the full evidential context.
Can image metadata be examined?
Yes. Digital image files typically contain embedded metadata — known as EXIF data — that may record information such as the camera or device used, the date and time of capture, GPS location coordinates, camera settings, and software used for processing or editing. Forensic examination of image metadata can provide valuable evidence, though it is important to note that metadata can be altered or removed, and should always be interpreted in the context of the broader technical and evidential picture.
Can an edited image be detected?
Forensic image examination can identify indicators consistent with post-capture editing. Common indicators include JPEG double-compression artefacts (arising when an image is re-saved after editing), inconsistencies in noise patterns across the image, lighting anomalies, cloning artefacts where content has been duplicated to conceal or replace areas, and inconsistencies between the metadata and the image content. The ability to detect editing depends on the nature and extent of editing, the tools used, and the image format and quality. Not all editing can be detected in all circumstances.
Can an image’s original source be identified?
Forensic examination may be able to assist in establishing information about the source of a digital image. EXIF metadata may identify the specific camera model or device. In some circumstances, camera identification techniques can link an image to a specific device through analysis of sensor noise patterns. The provenance of an image — its history of creation, processing and distribution — may be partially reconstructable from available metadata and technical characteristics, though this is subject to the limitations of available information.
Can AI-generated images be detected?
Digital image forensic examination can assess whether an image exhibits characteristics consistent with AI generation or AI-assisted manipulation. Current forensic methods can identify certain technical indicators associated with AI-generated imagery. However, it is important to be clear about the limitations: no forensic method can guarantee detection of all AI-generated images in all circumstances. The technology is evolving rapidly, and the absence of detected indicators does not constitute proof that an image is not AI-generated. Findings are always expressed as forensic opinions with appropriate qualifications.
Expert Witness Services
Expert Evidence & Instructions
Common questions about digital forensic expert witness services.
What is a digital forensic expert witness?
A digital forensic expert witness is a suitably qualified and experienced specialist who provides independent technical opinion to assist a court or tribunal in understanding complex digital evidence. Unlike a factual witness who gives evidence about what they personally observed, an expert witness is permitted to give opinion evidence — expressing a professional view on technical matters that are beyond the ordinary knowledge of the court. A digital forensic expert may give evidence about computer forensics, mobile device forensics, video evidence, digital image analysis, and related technical matters. The expert’s duty is to the court — not to the party that retains them.
What does a forensic expert report contain?
A digital forensic expert report typically contains: a statement of the expert’s qualifications and experience; the instructions received (terms of reference); the evidence examined; the methodology applied; the findings of the examination; the expert’s opinions — clearly distinguished from findings and expressed within the expert’s area of expertise; any limitations of the examination or the opinions expressed; and a declaration that the expert understands and has complied with their obligations to the court. The report is prepared to comply with the relevant expert witness code of conduct and the rules of the court in which it will be relied upon.
When should a solicitor engage a digital forensic expert?
A solicitor should consider engaging a digital forensic expert as early as possible in any matter where digital evidence is relevant. Early engagement allows the expert to advise on the preservation of evidence before it is lost or overwritten, to assess the scope of examination required, and to provide preliminary advice on the technical issues. Engaging an expert at a late stage — particularly after evidence has not been properly preserved — may significantly limit the options available. If in doubt about whether digital evidence is relevant to your matter, an early discussion with a forensic expert costs nothing and may save significant time and expense later.
Can a digital forensic expert challenge digital evidence?
Yes. An independent digital forensic expert can review and critically assess digital evidence produced by another party — including evidence gathered by police, prosecution, or opposing experts. This may involve examining the methodology used to gather and process the evidence, identifying any procedural issues, assessing whether the evidence has been correctly interpreted, and providing an independent opinion on the technical matters in dispute. This service is particularly important in criminal defence matters, where the accused is entitled to have prosecution digital evidence independently reviewed by a qualified expert.
What information should a solicitor provide when briefing a forensic expert?
When briefing a digital forensic expert, a solicitor should provide: a clear statement of the specific questions the expert is asked to address (terms of reference); copies of all relevant digital evidence or a description of the evidence to be examined; relevant factual background; any relevant witness statements, affidavits or other materials; any existing forensic reports from other experts; the procedural context (criminal, civil, regulatory); any relevant court orders or directions; and the required delivery date for the report. Clear, specific instructions produce better and more focused expert reports — and reduce unnecessary costs.
Criminal Defence Forensics
Defence & Independent Review
Common questions about digital forensics in criminal defence matters.
Can a digital forensic expert review prosecution digital evidence?
Yes. A defendant in criminal proceedings is entitled to have prosecution digital evidence independently reviewed by a qualified forensic expert. An independent examination may identify methodological issues in the prosecution’s forensic work, inconsistencies within the evidence, alternative interpretations of the data, or evidence that was not identified or disclosed by the prosecution. The role of the defence expert is to provide an honest, independent assessment — not to advocate for a particular outcome.
What can a defence forensic expert examine?
A defence forensic expert can examine any digital evidence relevant to the criminal matter — including computers, laptops, mobile phones, tablets, CCTV footage, digital images and associated electronic records. The examination may involve reviewing the prosecution’s forensic methodology, conducting an independent analysis of the evidence, identifying data that supports the defence case, or assessing whether the evidence has been correctly interpreted. The scope of examination is guided by the terms of reference provided by the instructing solicitor.
Can a forensic expert identify inconsistencies in digital evidence?
Yes. An independent forensic examination may identify inconsistencies in digital evidence — including internal inconsistencies within the data, inconsistencies between the digital evidence and other evidence in the case, issues with the methodology used to gather or analyse the evidence, or alternative explanations for findings that were not considered by the prosecution’s expert. Identifying such matters is an important part of the independent expert’s role and can be significant in the context of criminal proceedings.
Will a forensic expert try to prove my client is innocent?
No. A forensic expert witness does not advocate for a particular outcome. The expert’s role is to provide independent, objective analysis of the digital evidence — and to give an honest opinion about what that evidence does and does not show. If the independent examination reveals findings that support the defence case, those findings will be reported. If it does not, that will also be reported honestly. An expert who tailors their findings to achieve a desired outcome is not acting as a proper expert witness — and risks serious damage to their professional credibility and to the client’s case in court.
How early should a defence solicitor engage a digital forensic expert?
As early as possible. Early engagement in a criminal defence matter allows the expert to advise on evidence preservation before it is lost or overwritten, to review disclosure materials as they are provided, and to identify at an early stage whether independent forensic examination is likely to assist the defence. Engaging a forensic expert at a late stage — particularly after digital evidence has not been properly preserved, or after the accused has continued to use a relevant device — may significantly limit what can be achieved. An initial consultation involves no obligation.
Workplace Investigation
Employee & Corporate IT Matters
Common questions regarding digital forensics in the workplace.
Can an employer forensically examine an employee’s computer?
Generally, yes, if the computer is company property and the employer has appropriate workplace policies in place regarding IT usage and monitoring. Forensic examination of corporate assets is a standard procedure during investigations into misconduct or data theft. However, it is essential that the examination is conducted lawfully, proportionately, and in accordance with relevant privacy and employment legislation.
Can we prove that an employee copied files to a USB drive?
Digital forensic examination of a Windows or macOS computer can frequently identify which USB devices have been connected to the system, when they were connected, and in many cases, which files or folders were accessed or copied to those devices. This analysis of USB artefacts is a core component of investigating intellectual property theft and data exfiltration by departing employees.
Can deleted emails and internet history be recovered?
In many workplace investigations, deleted emails, browser history and chat logs can be recovered or reconstructed. The success of recovery depends on the corporate IT environment (e.g., Office 365 retention policies, local hard drive types) and how much time has passed since the deletion. Forensic examination can often recover fragments of deleted activity that are inaccessible to standard IT staff.
Can we forensically examine an employee’s personal mobile phone?
Generally, an employer cannot unilaterally forensically examine an employee’s personal device (BYOD) without their explicit consent, a contractual right, or a court order — even if corporate data is stored on it. The legal and privacy implications are significant. We strongly recommend seeking legal advice before attempting to acquire or examine personally owned devices.
Why use an independent forensic expert instead of internal IT?
Internal IT staff are skilled at keeping systems running, but they are rarely trained in forensic evidence preservation or chain of custody. Actions taken by IT staff to investigate an issue can inadvertently alter or destroy crucial metadata (like file access dates). Using an independent forensic expert ensures the evidence is preserved correctly, the investigation is objective, and the findings will withstand scrutiny in a tribunal or court.
