Skip to main content
24/7 emergency lineFree diagnosis on eligible standard recoveriesFREE Postage Label, Australia-wide
WildfireData Recovery
No Data, No Fee policyNo success fee unless we recover your data

Computer Forensics for Windows, macOS and Storage Devices

Owner-authorised computer forensics for Windows PCs, Macs, laptops and internal storage, including preservation, targeted examination and recoverable-data assessment.

Computer forensic work is question-led. We agree what must be preserved or located, which devices are in scope and how results should be documented before technical work begins.

Computers and storage we assess

  • Windows desktop and laptop computers.
  • Apple Mac desktop and notebook systems.
  • Internal SATA and NVMe storage.
  • External drives, USB devices and memory cards connected to a computer.
  • Available user files and system artefacts relevant to the agreed questions.
  • Damaged computer storage requiring recovery before examination.

Computer forensic questions we can scope

  • Preservation of a computer before repair, return or reassignment.
  • Identification and export of specified files or folders.
  • Assessment of deleted, formatted or inaccessible data.
  • Review of available file and system information relevant to an authorised matter.
  • Preparation of a defined evidence set for further professional review.
  • Documentation of acquisition steps, results and technical limitations.

What to do with the computer now

Stop ordinary use and avoid installing recovery or forensic tools. Do not reset the operating system, run cleanup utilities or open files to check them. Record the computer’s condition, date and time, connected devices, known accounts and any actions already performed.

If a hard drive is clicking, a laptop is liquid damaged or the computer will not power on, disconnect power when safe and tell us before shipping. The storage may need physical recovery before any forensic examination can proceed.

Our computer forensics workflow

  1. Instruction: we confirm ownership or authority, relevant computers, questions, date ranges and deadlines.
  2. Documentation: hardware identifiers, condition, supplied accessories and handling history are recorded.
  3. Preservation: an appropriate acquisition or recovery approach is selected for the storage and security state.
  4. Examination: available data is reviewed only against the agreed scope and search criteria.
  5. Quality checks: extracted material is validated and gaps, encryption or damaged areas are documented.
  6. Delivery: results, exports and technical notes are handed over through the agreed secure process.

Computer forensics or data recovery?

Computer forensics is used when the context, handling and evidential questions matter. Data recovery is used when the primary objective is restoring inaccessible files. Some cases require both. Learn about digital forensics, hard drive recovery and SSD recovery. If you suspect monitoring or remote-access software in a domestic or family violence matter, see domestic violence digital forensics.

Computer forensics FAQs

Should I turn the computer off?

Do not interact with it unnecessarily. The safest action depends on whether it is already on, encrypted, remotely accessible or physically damaged. Call for case-specific preservation guidance.

Can you examine both Windows and Mac computers?

Yes, matters can be assessed for Windows and macOS systems. Available acquisition and examination options depend on the model, storage, encryption and credentials.

Can deleted computer files be recovered?

Sometimes. SSD wear-levelling and TRIM, later computer use, encryption, overwriting and physical damage can limit recovery. Early preservation improves the assessment.

Do you need passwords and recovery keys?

Known credentials can be important for encrypted computers. Provide them only through the secure method agreed during intake, together with any relevant account information.

Can a lawyer or investigator instruct the work?

Yes, when they act for an authorised party and the authority, scope, communication path and intended deliverables are clear before work begins.


Start a computer forensic assessment

Tell us who owns or authorises the computer, what happened, which questions need answers and whether a legal or operational deadline applies.