Skip to main content
Cybersecurity · Defensive

Digital forensics: preserve the evidence, then show what happened

When fraud, misconduct or a breach is suspected, the first job is to preserve the evidence before it changes. Dark Pools collects evidence from laptops, phones, email and cloud accounts, fingerprints each item and records everyone who handles it, then analyses messages, documents and system logs to reconstruct who did what and when. Findings are reported for disciplinary, civil or criminal proceedings, with expert support.

How we engage
Laptops andcomputersPhonesEmail and cloudaccountsSystem logsDigital forensics
Defensive service · delivered by one accountable team
Outcomes

What you get

  • Evidence preserved before it can be altered or deleted
  • Each item fingerprinted, with a record of everyone who handled it
  • A timeline of who did what and when, built from messages, documents and logs
  • Findings reported in a form usable in disciplinary, civil or criminal proceedings
  • Expert support when the findings are tested
How we engage

The engagement, step by step

  1. 01ScopeAgree the question to answer, the devices and accounts in scope and the basis for collecting them.
  2. 02PreserveCollect evidence from laptops, phones, email and cloud accounts, fingerprint each item and start its custody record.
  3. 03AnalyseExamine messages, documents and system logs, and reconstruct the timeline of events.
  4. 04ReportSet out the findings, the evidence behind each one and the method used.
  5. 05SupportProvide expert support through disciplinary, civil or criminal proceedings.
Scope

What we cover

Laptops and computers

Forensic copies of drives, and the files, browser history and logs on them.

Phones

Messages, call records and files from mobile phones.

Email and cloud accounts

Mailboxes, shared drives and the activity logs that cloud services keep.

System logs

Records of sign-ins, access and changes across your systems.

Deliverables

What you receive

  • 01Evidence register with the fingerprint (hash) of each item
  • 02Chain-of-custody record for every item
  • 03Timeline of events
  • 04Findings report
  • 05Evidence pack of numbered, fingerprinted exhibits, redacted where needed and sealed so it can be checked later
FAQ

Questions buyers ask

Get started

Take the next step

Scope digital forensics with a security lead. We will tell you plainly what you need, and what you do not.

All cybersecurity services