Your company reputation is something that when you lose you can’t get back. Now think of how you can defend against that?

David Willson

The answers to the most fundamental litigation questions – the “who, what, where, when, and why” – are often contained in electronically stored information (ESI), which can be retrieved through electronic discovery (e-discovery) and/or computer forensics.

Before your investigation get out of hand you need to understand both the applications and parameters of e-discovery and computer forensics as it can be critical to the outcome of a litigation.

The primary focus of standard e-discovery is the collection of information that is active or undeleted and its metadata; which tells us about the document’s author, time of creation, source, and history. Information readily available to the user, such as e-mail, electronic calendars, word processing files, and databases from multiple hard drives, social media and other locations. Data collected in e-discovery can be limited; for deeper recovery where computer forensics tools and techniques are often used.

The goal of computer forensics is to conduct an autopsy of a computer hard drive – searching hidden folders and unallocated disk space to identify the who, what, where, when, and why from a computer. A significant amount of evidence is not readily accessible on a computer; when this occurs, a computer forensic examination is necessary.

Information gleaned from a computer forensics investigation can be very beneficial to many types of litigation and proceeding.

Computer Forensics can recover:

  • Automatically stored data: Data automatically stored by the computer, such as an automated backup. A file that has been deleted may still exist as backup or temporary copy on the users hard drive.
  • Deleted files: “Deleted data often remains on a hard drive until it is overwritten or forensically wiped. .
  • Residual or “ghost” data: Data that remains recoverable from a computer system, but isn’t readily accessible, such as deleted files or file fragments. .
  • System data: An electronic history of activity on a computer or network such as login, last users, print logs and more. .
  • Wiping software: Detecting if wiping software has been used can identify potential malicious intent, tampering or advanced user capability. .

Preservation of the original evidence is absolutely crucial to any investigation and to maintain admissibility of the evidence. Creating a mirror image of the evidence device produces an exact duplicate, bit for bit, of the original evidence that allows investigator’s use without alteration of the evidence.