Technical investigation, Sydney

Bring me the whole problem.

For people and organisations facing a confusing technical incident, I help establish what happened and what remains unknown. I examine the computer, phone, accounts, network, wireless and deleted material together.

Output
Findings, maps, chronology and a handover
Method
Eight stages, with evidence first
Rate
$1,000 a day, plus GST
Reply
Within one business day

How I work through it

I start with the question you need answered. I record what I examine, what it shows and what remains unknown.

  1. Understand

    I listen to what happened, identify devices and accounts, and record immediate risks and the questions that need answers.

  2. Preserve

    I photograph, record, acquire, export and hash material within scope. I preserve evidence before changes that could remove it.

  3. Analyse

    I examine computer, phone, account, network, cloud and deleted material. I include RF observations where relevant.

  4. Correlate

    I bring the records into one timeline, account map, device map and evidence register.

  5. Explain

    I separate what is known, likely, possible and unknown. I explain what the evidence supports and what I can test next.

  6. Recover

    I work on recoverable files, account access through available routes and systems, subject to what survives and what is accessible.

  7. Secure

    After preservation, I address passwords, MFA, devices, networks, backups and privacy controls within the agreed scope.

  8. Handover

    I prepare the records for you or an appropriately instructed solicitor, insurer or specialist. I state what still needs examination.

The whole environment belongs in the question

A device, an account and a wireless observation can be parts of the same concern. I test the connections instead of assuming they share a cause.

Devices

Computer, phone and deleted material

I examine available device records and recoverable files. In one matter, I examined five phones. That describes the scope of one engagement, not a result to expect.

Accounts

What controls what

I map accounts, recovery routes and trusted devices. I compare account events with device records and the timeline.

Network

Connections and wireless activity

I investigate network records and relevant RF observations. I record a persistent transmitter as a frequency, level and pattern, then investigate.

Evidence

One record for the next person

I organise findings, source references and unresolved questions so another examiner or your lawyer can follow the technical work.

What I do here, and where I bring in a specialist

I separate available capability from work needing preparation and work that must be handed over. The scope records which route applies.

In house

In house capability

Logical acquisition, disk imaging, deleted recovery, evidence databases, network investigation and SDR surveys, using the equipment and methods available here.

Specialist

Specialist engagement

Extended RF monitoring, complex incidents across devices and legal technical review need an agreed scope and preparation.

Escalation

Partner or escalation

I preserve and prepare material for specialists when the work needs chip off extraction, cleanroom repair, advanced TSCM or independent opinion and testimony.

The lab behind the work

Twenty years of buying things because "that might be useful one day" has built a workshop for examining how systems fit together.

Storage

Computers, servers and storage

My lab includes computers, storage arrays, NAS, servers, disk imaging systems and USB, NVMe and SATA adapters.

Radio

Networking and radio equipment

I have networking gear, SDR receivers, antennas for several bands, Bluetooth hardware and LoRa development boards for scoped investigation.

Compute

Local analysis and test equipment

Mobile devices, test equipment and local AI and GPU compute support the work. I choose the setup for the question and state the limits.

The limits, before work starts

I describe what the evidence shows. A report cannot promise a legal outcome.

Overwritten data cannot be recovered. Physically failed media needing a cleanroom is referred on. I prepare material for specialist chip off extraction when required.

RF detection is not attribution. A signal is not a proven bug or a proven person. I report frequency, level and pattern before investigating. Advanced TSCM goes to specialists.

I report what the evidence shows and cannot promise a legal outcome. Independent specialist opinion and testimony beyond my scope are escalated, with the underlying material preserved for handover.

What it costs

I quote each matter before work starts, from $1,000 a day, plus GST. The scope sets out what I will examine and what you will receive. Reply within one business day. All prices are in AUD, plus GST.

Questions before you start

Do I need to know which service to ask for?

No. Tell me what happened and what you need to understand. I identify the technical questions and which parts I can examine. You do not need to know what kind of specialist you need before making contact.

Will you take an unusual concern seriously?

Yes. I take the concern seriously and test what can be tested. I separate what you observed from possible explanations. The evidence comes first, including when it does not support a suspected cause.

Can you look at devices and accounts together?

Yes. The scope can cover the computer, phone, accounts, network, wireless environment and deleted material together. I compare available records and identify where access or missing evidence limits the answer.

What happens before you change anything?

I identify preservation needs and immediate risks. I record, acquire and export relevant material within scope before recovery or security changes that could remove evidence.

What happens if another specialist is needed?

I explain the boundary and prepare the technical material for handover. Chip off extraction, cleanroom work, advanced TSCM and independent opinion or testimony beyond my scope need an appropriately instructed specialist.

What will I understand at the end?

The report sets out what I examined, what the evidence shows, what remains unknown and what I can test next. Maps and a chronology connect the sources. It cannot promise that every question will have an answer.

Tell me what happened. I will help define the technical questions.