Workstation Deep Imaging

An image is the cheapest insurance in this trade and the one most often bought too late. Once a machine is wiped and reissued, every question anybody thinks of afterwards has no answer, and no amount of money reverses that. A capture takes the disk exactly as it stands, verifies it, seals it and files it — and the hardware goes back into service. £400 + VAT preserves and extracts; £800 + VAT adds the examination and its written report.

Authority first. Bench afterwards. The full examination, written up as a report, comes to £800 + VAT. Stop at a verified image with its deleted material extracted and nothing reported, and it is £400 + VAT — the rung a recorder disk already occupies. Diagnosis is free and the scope is agreed in writing beforehand. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Ordinary recovery bands are on the data recovery cost page.

// machines that belong ahead of the queue

When to capture rather than wipe

Any single one of these justifies taking an image before the machine is touched again.

A leaver's laptop in the IT cupboard with a reissue ticket open against it
Kit named in a live dispute that is already on a disposal schedule
A returned machine still sealed behind BitLocker or FileVault
Any prospect that chat history or discarded work will be wanted later on
Unanswered questions about browsing, remote sessions or VPN use
An allegation that the disk was erased before it came back

Capture this week, reissue next week

The conflict here is practical rather than legal. IT wants the asset back in circulation and the lawyers want it untouched, and those two positions look irreconcilable until somebody takes an image. Once a verified copy exists the physical machine stops being evidence and becomes a laptop again. In most cases that is a day or two out of service, not a month, and the copy is good for as long as the file is kept. The failure mode is always the same and always avoidable: a device gets rebuilt in week two because nobody had authority to say no, and in week nine somebody asks what was in the downloads folder.

What a full capture is still holding

A disk image is not a copy of the documents. It is a copy of the volume, including the parts the operating system does not show you. Deleted files still sitting in unallocated space. Browser history, cache and cookies, which reconstruct research, uploads and sign-ins in some detail. The page file and the hibernation file, which frequently hold fragments of documents that were open, chat that was on screen and occasionally a credential. Local Teams and Slack stores, including conversations since deleted from the server. Registry hives carrying the device register and the software history. VPN and network records placing the machine on a particular network at a stated hour. None of that survives a rebuild, and none of it can be reconstructed afterwards.

Encrypted machines, taken while the keys still exist

BitLocker and FileVault are the most common reason a capture goes wrong, and almost always for an administrative reason rather than a technical one. A volume can be imaged while it is locked, but the image is useless without a key, and the key has a habit of leaving with the person. BitLocker recovery keys are normally escrowed to Active Directory, to Entra ID or to a Microsoft account; FileVault keys go to a management platform or to the user's Apple account. Retrieve the key first, capture second, and record where the key came from. Where no key exists anywhere the answer is that the volume cannot be read, by us or by anybody, and that is said on the telephone rather than discovered after two weeks. <a href="bitlocker-recovery.html">BitLocker recovery</a> covers the non-forensic version of the same problem.

Testing the claim that the drive was wiped

A machine handed back freshly reinstalled is not the dead end it is assumed to be, and it is often more informative than one handed back untouched. A quick reinstall leaves most of the previous volume in unallocated space. It also leaves timestamps: the installation has a date, and if that date sits between the resignation and the handover, the fact is worth stating on its own. Erase utilities leave prefetch entries, installation records and a characteristic pattern on the surface. A full multi-pass wipe of a spinning disk does genuinely destroy the contents — in which case the finding is that a wipe was performed, by which tool and at what hour, and that finding tends to be worth having.

The method and custody standards behind every capture are at the forensic recovery hub, the obligations that make a capture necessary are at legal hold and chain of custody, and what an image is then asked is at deleted-file forensics and USB device forensics.

// what one image keeps hold of

Six things a single capture preserves

All of it comes from one acquisition. None of it survives a rebuild, and none of it can be recreated later.

The container

An E01 holding the whole volume, mountable and checkable by any examiner.

Proof it is unchanged

SHA-256 taken at acquisition and matched again at every verification since.

Browsing

History, cache and cookies, rebuilding research, uploads and where somebody signed in.

Memory spill

Page file and hibernation data: documents left open, chat on screen, the odd credential.

Local chat stores

What Teams and Slack kept on disk, server-side deletions included.

Network trail

VPN sessions and connection records fixing the machine to a network at an hour.

// what it costs, and who is entitled to ask

The fee, and the authority behind the instruction

Two figures, published rather than implied

The least popular sentence first. Forensic work does not sit under no fix, no fee. That guarantee belongs to logical recovery, and the exclusions published beside it are electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs. An examination is bench hours spent answering a question you have asked, and the hours are the same whether the answer helps your case or wrecks it. Against that, two figures are printed here rather than quoted on application, which is two more than most laboratories will commit to in public. Where the examination finishes with a full written report the fee is £800 + VAT. Where it finishes at the evidence — a verified binary image with the deleted material lifted out of it, handed to your solicitor or to another examiner to interpret — the fee is £400 + VAT. That lower figure is the same rung as a recorder disk or a BitLocker volume, so nothing on this page invents a sixth band.

£800 + VAT

The examination plus the written report it produces, set out so that an expert paid to disagree with you can follow every step and try to break it.

£400 + VAT

The verified binary image with its deleted material extracted, and no report written. The rung a recorder disk or an encrypted volume already occupies, not an extra band.

Both assume a single machine and a single question asked of it. Eleven laptops, a file server and a tenancy export is a larger exercise altogether, so anything spanning several devices is measured during the free diagnostic and written down before you are asked to agree to it. Working out what is there costs nothing and still closes 2 working days after the device is booked in at Cambridge, and the fee is settled before an examiner opens the image rather than after the findings are known. Anything that is not forensic keeps the band it has always had on the prices page.

The footing an examination has to stand on

Capture work is done on hardware the business owns and issued, or on written instruction from a solicitor or the court. Three routes reach this bench and there has never been a fourth. Kit the business bought and issued to somebody. A written instruction from a solicitor, an insurer or the court. Or a device that genuinely belongs to the person asking, which in a family matter means owned outright or owned jointly. Nothing is broken into here. Somebody else's password is not worked out, monitoring software is not installed on a device the client does not own, and live traffic is never intercepted — interception belongs to the bodies named in the Investigatory Powers Act 2016 and to no private laboratory. Where a client has no lawful right to look inside a device, instructing us does not manufacture one. Handsets and tablets are outside the practice altogether.

// how the media reaches Cambridge

Sending a device — and the three exceptions

Send the drive rather than the whole machine wherever the disk comes out, and ring 0800 689 0668 first so the packaging and the paperwork are agreed. Nothing is collected anywhere in this network and there is no Leicester counter: it goes to Cambridge by tracked, insured post, or over the counter there in office hours. Storage soldered to a mainboard, as on Apple Silicon machines, cannot be removed and cannot be posted.

The general rule is the drive travels and the machine stays behind — out of the laptop, out of the tower, out of the iMac, out of the recorder under the counter. This bench does not dismantle equipment, and a repair shop will do it while you wait. Three things are the other way round, and getting them wrong costs you the recovery: an external drive stays sealed in its own case, a NAS comes as a complete unit, and a WD My Passport or My Book travels whole with its cable, because on those the encryption key is held on the bridge board rather than on the disk — separate the two and the data becomes unreadable even to us. A Fusion Mac needs both of its drives, each labelled. The one thing nobody can work round is flash soldered onto the mainboard, as on Apple Silicon machines: if it will not come off, there is nothing to post.

  • A stiff box or a well-padded mailer, with enough packing that nothing moves when you shake it. Power supplies, docks and cables can stay at home unless the drive is one of the WD units above.
  • Running a RAID or a server? Send the member disks on their own, not the chassis or the controller, and write the bay order on each one — 1, 2, 3 and so on. Photograph the front of the unit before you pull anything, because that photograph occasionally saves a day of work.
  • Fill in the shipping and booking-in form (PDF) — a name, a number you actually answer, and a line on how the trouble started — and put it in the box.
  • Special Delivery is tracked and insured and is what most people use; your own courier is equally fine. Handing it over in person also works: reception at the Cambridge address takes devices across the counter, Mon–Fri 9:00am–5:30pm. What does not exist is a Leicester counter or anyone who comes to collect.
// write this on the label

Cambridge Data Recovery

Compass House
Vision Park, Chivers Way
Cambridge, CB24 9AD

↓ Print the shipping & booking-in form (PDF)

Address it to Cambridge Data Recovery. It is about seventy miles from Leicester if you fancy driving it — M1 south to Junction 19, then the A14 east — and the lab is two minutes off Junction 32 with parking at the door. Posting costs you a stamp and a day instead. Whichever you choose, you hear from us the moment it is booked in, and the free diagnostic closes two working days after that.

Not certain what belongs in the box? Ring 0800 689 0668 before you tape it up, or let the free online diagnostic ask the questions for you.

// imaging a machine — before you decide

What IT departments ask first

That is the usual outcome and the main reason to image it. Once the capture verifies, the physical machine has no further evidential job to do and can be rebuilt and handed to the next person. Keep the image and the custody file, not the hardware. Where the machine itself is likely to be inspected by the other side, that is a decision for the solicitors and it should be taken before anybody schedules a rebuild.
Usually not, and it is worth saying so before anyone panics. Somebody browsing folders changes access times and adds a little activity, both of which are visible and can be excluded from the analysis. What genuinely does damage is a rebuild, a wipe or a disk repair utility. If people have been looking, write down who, when and what they opened, and the report accounts for it rather than tripping over it.
Go and find the recovery key before anything else happens. It is normally escrowed to Active Directory, to Entra ID or to the Microsoft account the device was enrolled with, and a great many organisations have it without realising. The volume can be imaged locked, so the capture does not have to wait, but nothing can be read out of that image until a key appears. If none exists anywhere, the honest answer is that the data stays shut.
Almost always. A quick reinstall leaves most of the old volume intact underneath it, and even a genuine multi-pass wipe leaves the fact, the tool and the hour of the wipe behind. In an employment matter, evidence that a company laptop was deliberately erased between the resignation and the handover can matter as much as whatever was on it.

Rebuild it next month. Image it this week.

A verified copy takes a day or two and lasts as long as you keep the file. A rebuild takes an afternoon and lasts for ever.