Forensic data recovery, Sydney
The media is copied before it is read, the copy is hashed, and the work happens on the copy. What comes back is files plus a written account of where each one came from.
- Covers
- Disks, cards, phones, servers
- Output
- Files, hashes and a written report
- Area
- Sydney and New South Wales
If you just want the photos or documents back off a dead laptop and nobody is going to argue about them later, a general data recovery service will do that faster and for less than this.
What you pay for here is the evidence trail around the recovery. That matters when a file is going to a lawyer, an insurer, a regulator or a tribunal, and it is wasted money when the file is only going back onto your desktop.
What forensic recovery adds
Order
Image first, read second
The media is copied sector by sector before anything reads it, and the examination runs on the copy. The original goes back in the bag in the state it arrived.
Integrity
A hash on both ends
The image is hashed when it is taken and again when it is used, so anybody can check later that what was examined is what was received.
Custody
A record of who held it
What was received, when, from whom, in what condition, and where it was kept. Written down at the time, not reconstructed afterwards.
Output
A report, not just a folder
A written account of what was recovered, where on the media it came from, what could not be recovered, and what that means.
When this is the right service
- Somebody left and files went with them, and it has to be shown rather than asserted.
- Deletion is alleged and the question is what was on the device and when it went.
- A device sits at the centre of a dispute and both sides will look at the result.
- An insurer or a lawyer needs the source examined, not a copy of a copy emailed around.
- The recovered files have to be handed on with a record of how they were obtained.
How the work runs
Receive
The media is logged in: what it is, what condition it arrived in, who handed it over and when.
Image
A sector level copy is taken with the source write protected, and the copy is hashed. Failing media is imaged in passes rather than pushed.
Recover
Filesystem structures are rebuilt where they survive, and data is carved from free space where they do not.
Report
Findings in writing, with the hashes, the method and a plain statement of what could not be recovered.
The limits, before you spend anything
What cannot be done
- Data that has been written over is gone. Nothing recovers it.
- Encrypted data without the key or passphrase stays encrypted.
- Media with a physical failure that needs a cleanroom is referred on, not handled here.
- A report says what the evidence shows. It cannot promise a legal outcome.
- No recovery is guaranteed, and no percentage is claimed for one.
What decides the outcome
- Stop using the device. Every write reuses the free space deleted data lives in.
- Do not run a recovery tool over it first. Most of them write to the disk they are reading.
- Do not reformat, reinstall or let anybody try a quick fix.
- If it is making a noise it did not make before, power it down and leave it down.
- Write down when it was last used and what happened just before.
What it costs
Work is quoted per matter before it starts. The rate below is what that quote is built from.
That rate is $1,000 a day. All prices are in AUD, plus GST.
The examination that establishes what is possible is quoted first and on its own, because nobody can price the rest honestly before the media has been looked at.
See the rate in fullRelated work
- CCTV footage recovery when the media is a DVR or NVR disk.
- Phone and computer forensics when the question is what the device did, not just what it held.
- Digital forensics for the matter the recovery sits inside.
Questions worth asking first
I just want my photos back. Is this the right service?
Probably not. If nobody is going to argue about the files later, a general data recovery service will do it faster and for less than this. What you pay for here is the evidence trail around the recovery, not the files on their own.
Can you guarantee you will get the data back?
No, and nobody honest can. Whether data comes back depends on what has been written over the top of it and on the physical state of the media. Both are known only after the media is examined, which is why the first stage is quoted on its own.
What is the difference between this and normal data recovery?
The output. Normal recovery hands you the files. Here the media is imaged first, the image is hashed, the work happens on the copy, and you get a written report saying what was found, where it came from and what could not be recovered.
The drive is making a clicking noise. Can you open it?
No. Media with a physical failure that needs a cleanroom is referred on rather than handled here, and opening it on a bench would destroy what is left. Power it down and leave it alone until somebody who can image it safely has it.
The files are encrypted. Does that matter?
Yes. Encrypted data without the key or the passphrase stays encrypted. Recovering the encrypted blocks is possible and is sometimes still worth doing, but nothing here breaks encryption to read them.
Should I keep using the computer while I wait?
No. Every write reuses free space, and free space is where deleted data lives. Shut it down, leave it off, and tell us when it was last used. That single decision usually matters more than anything done later.
What does it cost?
Work is quoted per matter before it starts. The rate that quote is built from is $1,000 a day, plus GST. The examination that tells us what is possible is quoted first and on its own.