Call us — 0141 404 0294
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Trust, Practice & Honest Limits · Instructed, Not Just Commissioned

Forensic Examination of a Device in a Legal Matter

His enquiry concerned a device that is not simply his to have looked at. A USB drive "provided to me as part of an ongoing legal proceeding", for which he wants professional examination "to determine its contents, any deleted or hidden data, metadata, and potential details about its origin or previous usage," noting the sensitive nature of the device as potential evidence. Two things need saying, and the first is more important than anything technical. Forensic examination in live proceedings should be commissioned through his solicitor, not arranged privately — because how the work is instructed determines whether its findings can be used at all, and that is a distinction people discover far too late.

MediaUSB flash drive disclosed within ongoing legal proceedings — examination sought covering existing content, deleted and hidden data, metadata and indications of prior use
Reported situationDevice received as part of a live legal matter · evidential status acknowledged by the enquirer · full forensic analysis requested · instruction route not yet established
Fault classNot a fault — forensic examination requiring documented continuity, defensible methodology and reporting suitable for proceedings
Equipment usedInstruction route confirmed before examination · continuity documented from receipt · write-blocked forensic imaging with hash verification · analysis performed on the image only (OSForensics) · findings reported with methodology and limitations stated

The decode: instruction, method, and what analysis can honestly establish

Why the instruction route matters most: forensic findings are only as useful as their standing. Work commissioned informally by a party can be challenged on grounds that have nothing to do with its technical quality — who instructed it, what they asked for, whether the examiner understood their obligations, and whether the process was documented. Where an examiner is instructed properly through solicitors, the scope is defined, the duties are clear, and the report is produced in a form the proceedings can use. That costs nothing extra to arrange and it is the difference between a report that helps and one that is set aside. Anyone doing this work should say so before taking the device, which is why it leads this page.

What continuity means in practice: from the moment the device is received it is logged, identified, sealed and its handling recorded — who had it, when, and what was done. Examination is performed on a write-blocked forensic image with cryptographic hashes taken to demonstrate the copy matches the original and that nothing was altered. The original is not analysed, browsed or connected to an ordinary computer. That discipline is not ceremony; it is what makes the findings defensible.

What examination can genuinely establish: a good deal. Existing files and their metadata. Deleted content still physically present, and fragments in unallocated space. Filesystem artefacts indicating file creation, modification and deletion. Evidence of formatting, of prior filesystems, and sometimes of devices the drive was connected to. Serial and manufacturing identifiers. Traces of software having been run from it.

What it cannot, and this belongs in any honest answer: timestamps record what a system recorded, and system clocks can be wrong, adjusted, or in another time zone; a file's dates describe operations rather than intentions. Analysis can rarely establish who performed an action, only that it occurred on a device. And absence of evidence is not evidence of absence — a device that shows no trace of something may never have held it, or may have been wiped in a way that leaves little. A report that states its limitations is worth more than one that overreaches, and an examiner who cannot tell you what their findings do not show is not one to instruct.

What must not happen meanwhile: the device should not be plugged into anything. Connecting a drive to an ordinary computer modifies it — access timestamps change, the operating system writes indexing and recovery data — and that alters the evidence and gives anyone reason to question everything that follows.

On the bench

The instruction route was confirmed before the device was examined, since findings produced outside a proper instruction can be challenged regardless of their quality. Continuity was documented from receipt — the device logged, identified, sealed and its handling recorded throughout. A write-blocked forensic image was taken with cryptographic hashes demonstrating that the copy matched the original, and every subsequent step was performed on the image alone through OSForensics: existing content, deleted material and unallocated space, filesystem artefacts, metadata and device identifiers. The report set out the methodology, the findings, and — explicitly — their limitations.

The outcome

The examination properly instructed, continuity documented, analysis performed on a verified image and the findings reported with their limitations stated. CCTV and forensic investigation work is charged at a flat fee, with 50% payable upfront to begin the investigation, and the balance due only on completion. The decode, for anyone holding a device that is evidence: have the examination instructed through your solicitor rather than arranged privately, because how it is commissioned determines whether the findings can be used and that is discovered too late otherwise; expect documented continuity, a write-blocked image with hash verification, and analysis performed only on the copy; understand that timestamps record system operations rather than intentions and rarely establish who did anything; and do not plug the device into anything, because connecting it changes it.

Device that forms part of a legal matter

Don't plug it into anything, and don't commission the examination yourself. Connecting a drive to an ordinary computer alters it — access times change and the operating system writes indexing data — which damages the evidence and hands anyone a reason to question everything that follows. More importantly, speak to your solicitor first: forensic work in live proceedings should be instructed through them, with the scope defined and the examiner's obligations clear, because findings arranged privately can be challenged on grounds that have nothing to do with their technical quality. Expect any competent examiner to tell you this before accepting the device. Then expect documented continuity from receipt, a write-blocked image with cryptographic verification, analysis performed only on the copy, and a report that states plainly what its findings do not show as well as what they do.

Device that is potential evidence?
Speak to your solicitor first — then call Glasgow Data Recovery on 0141 404 0294; continuity documented from receipt, write-blocked imaging with hash verification, findings reported with limitations stated.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.

0141 404 0294