Forensic Process

Flashback Data follows the U.S. Department of Justice Guidelines for Seizing and Searching Computers. We recommend that a chain of custody form be started for each case upon leaving each client's possession.

The full forensic process varies between cases, but the general procedures are as follows:


  1. A bit-by-bit image is created from the suspect media ensuring that an exact, untampered copy is used for the investigation.


  2. The forensic image is analyzed for potential evidence specific to each case. Deleted files, internet history, Instant messaging logs, emails, etc are all searched.


  3. Evidence is then extracted and prepared for use in court.


  4. The investigator will then create a custom report detailing the findings.


  5. Expert witness testimony is provided if needed.

 

forensic process

Please contact Flashback Data today for more information on any of our computer forensic related services.