02 · Forensics

Computer & Mobile Device Forensics

Endpoint-level truth, recovered and interpreted.

Overview

Detailed forensic analysis across desktops, laptops, and mobile devices — recovering deleted data, reconstructing user activity, and surfacing the artifacts that matter to an investigation.

Capabilities

What engagements deliver.

Each engagement is scoped to the incident. The capabilities below define the outer envelope of what we bring to the work.

C.01

File system & disk-level analysis

Low-level parsing of NTFS, APFS, ext4, and mobile file systems to reveal what the OS prefers to hide.

C.02

Recovery of deleted or hidden data

Carving unallocated space, slack, volume shadow copies, and encrypted containers for recoverable artifacts.

C.03

Application & communication analysis

Messaging, browser, and productivity app artifacts reconstructed across versions and device states.

C.04

Mobile device extraction

Logical, file-system, and physical acquisitions across iOS and Android, interpreted for investigative context.

Acquisition Bench

Custodian endpoints, handled one by one.

Every device entering our lab is logged, photographed, hashed, and tracked through acquisition, analysis, and release.

WS-01imaging
Laptop / macOS
SHA-256 verified
WS-02acquired
Laptop / Win11
SHA-256 verified
MB-07queued
iPhone 15
SHA-256 verified
MB-11acquired
Pixel 8
SHA-256 verified
WS-14analysis
Desktop / Win11
SHA-256 verified
EX-03acquired
External SSD
SHA-256 verified
MB-22analysis
iPhone 13
SHA-256 verified
WS-08acquired
Laptop / Ubuntu
SHA-256 verified

When the incident starts,
the clock already has.

Reach an ISRM investigator directly. First call to engaged team, under an hour.