Workstation Deep Imaging

Every returned laptop has one forensic moment, and it sits between hand-back and rebuild. Captured then — behind a write-blocker, into E01 evidence files, verified by SHA-256 — the machine goes on answering questions for years. Returned to service instead, it answers fewer of them every week. For employers from the Baltic Triangle studios to university departments and the offices of the commercial district, the rule is short: the questions will wait, the image will not.

Scope first, then work. Diagnosis is free and comes at the beginning; the written scope follows, and the forensic fee is paid in full before an examiner opens the image. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. The whole price list sits on the data recovery cost page.

// which machines to capture

Machines to image before anything else

Any one of these puts a machine on the list, ahead of the rebuild queue.

A leaver's laptop is with IT, waiting to be reissued
A machine involved in a dispute is booked for rebuild or disposal
A BitLocker or FileVault device has been left behind by its user
Deleted files or chat history may be wanted at some later stage
Browsing, VPN or remote-access activity has been called into question
A drive is thought to have been wiped on purpose

Capture first, reissue afterwards

The arithmetic is one-sided. An image taken today — the disk read behind a write-blocker into E01 files and verified by SHA-256 — costs a fraction of what the same evidence is worth once there is a dispute to spend it on, and the hardware returns to service afterwards because the evidence no longer depends on it. Skip the image, reissue the laptop, and every day of the new user's work settles over the last user's traces. Firms that image every leaver's machine as routine never have to explain an absence.

What a full capture preserves

A great deal more than the documents. Browsing history, cache and cookies reconstruct research and uploads. Drafts and copies nobody consciously saved sit among the temporary files. Fragments of memory — a document left open, a chat window, occasionally a credential — persist in the pagefile and the hibernation file. Slack and Teams keep local caches that return conversations deleted from the applications themselves. VPN and connection logs place the machine on given networks at given hours. A rebuild removes all of it. A capture keeps it.

Encrypted machines, taken while the keys exist

Encryption rewards acting early. A device protected by BitLocker or FileVault should be imaged while the keys remain in escrow and the passwords are still known, before the leaver's account is closed, the directory tidied, or the TPM cleared by a rebuild. On a live, unlocked Windows volume there is a second route: Volume Shadow Copies taken from the running system, which sidestep the encryption question because the volume is open while you hold it. Encrypted-volume work counts as forensic and, like everything else on this page, is paid for in advance once the scope is agreed.

Testing a claim that a drive was wiped

A claim of wiping is tested, not accepted. Erase utilities and boot tools, DBAN among them, leave their own evidence: boot records, tool signatures, the pattern an overwrite writes across the platters, and timing that can be set against everything else happening that week. Interrupted and partial runs are frequent and leave whole regions recoverable, while a hardware erase command can be read against the drive's own logs. If the wipe did complete, the report says so and dates it, because deliberately wiping a drive as proceedings approach is a finding in its own right.

Custody and verification are described at the forensic recovery hub. How deletion evidence reads on a copy belongs with deleted-file forensics, and the duty to preserve with legal hold and chain of custody. The numbers are on the prices page.

// what a capture is still worth later

Still answering questions two years on

Taken once, verified once, and available for whatever the dispute asks later.

E01 files

The whole disk in a container any examiner can open and verify.

Hash values

SHA-256 proving the image, and each copy taken from it, unchanged.

Browser artefacts

History, cache and cookies reconstructing research and uploads.

Memory remnants

Pagefile and hibernation contents: documents, conversations, credentials.

Chat caches

Local Slack and Teams stores, with deleted conversations recovered.

Connection records

VPN and network traces placing the machine on networks at set hours.

// the fee, and who may instruct

The fee, and the basis we require

The price, without hedging

Diagnosis is free and takes 2 working days from the morning the parcel is opened. Nothing forensic runs under no fix, no fee. A forensic investigation ending in a written report is £800 + VAT, settled in full before the examination opens. Where no report is wanted, the binary image with deleted-file extraction stands on its own at £400 + VAT. Forensic work is paid for in advance, without exception. BitLocker and other encrypted-volume work counts as forensic and is paid for in advance on the same terms. The same two figures appear on the prices page, and you are asked for nothing until the written scope has been agreed.

Who may instruct

Imaging runs on company-owned machines, on hardware you own yourself, or under a solicitor's instruction. Only three routes reach an examination and there is no fourth. Hardware the business itself bought. A written instruction from solicitors, from an insurer or from the court. Or a device belonging to the client, which in a family matter extends to a machine the couple own between them. Nothing is broken into on this bench. Live traffic is never intercepted: that power belongs to the agencies named in the Investigatory Powers Act 2016 and nowhere else. If a client may not lawfully look inside a device, the answer here is the same one.

// posting your device in

Sending it in — a padded box and a label

Tell us how many machines are involved and where you stand on encryption when you ring 0800 689 0668, and the capture is scoped in writing. Nothing is collected anywhere in this network, so the drives go by tracked, insured post to the Manchester laboratory and custody is recorded at booking-in.

Still screwed inside a laptop, tower, MacBook, iMac, server or a CCTV recorder? Take the drive out and post that on its own. We do not strip machines here, and any computer shop will do it in a few minutes. The one job nobody can take on is flash soldered straight to a logic board, as on Apple Silicon Macs and a handful of very slim laptops: if the storage will not unbolt, there is nothing to send.

  • Wrap it well and use a box or padded envelope stiff enough that nothing rattles. Hold on to the cables, caddies and power supplies; they are no help at this end.
  • Fill in the shipping and booking-in form (PDF) — name, number, and a line or two about what went wrong — and drop it in the box beside the drive.
  • Royal Mail Special Delivery gets it here tracked and insured. Book your own courier instead if you prefer; either way the parcel is signed for.
  • Driving over instead? Reception at the Manchester address below accepts drop-offs, Mon–Fri 9:00am–5:30pm. What there is not, anywhere, is a Liverpool counter or a collection service.
// the address on the parcel

Manchester Data Recovery

Manchester Data Recovery
Peter House, Oxford Street
Manchester, M1 5AN

↓ Print the shipping & booking-in form (PDF)

Address it to Manchester Data Recovery. It is roughly 35 miles from Liverpool along the M62 if you fancy the run, and next working day by tracked post if you do not. We ring or email the moment it is booked in, and the free diagnostic closes 2 working days after that.

Not sure what belongs in the parcel? Call 0800 689 0668 before you tape it shut, or step through the free online diagnostic first.

// workstation imaging — before capture

What IT teams ask before capture

Usually, which is precisely why the image is taken before it goes. The verified copy becomes the evidence and the hardware goes back to being a laptop. The exception is a live dispute in which the device itself may have to be produced; there your solicitor decides and we keep it sealed.
Weakened rather than ruined. That session moved some dates and the report will record it, but the registry, the journals, the caches and unallocated space survive somebody having a look round. Write down what was done and when, stop at that, and take the image.
Leave the directory alone. The recovery key is usually still held in Azure AD, Intune or the Microsoft account tied to the machine. Image first, unlock against the copy, and do it before accounts are closed and passwords cycled. The work counts as forensic, is scoped after the free diagnostic, and is paid for in advance.
Test it. A surprising number of advertised wipes prove partial, interrupted or misconfigured, leaving recoverable regions, and the wipe itself can be named, dated and attributed — occasionally worth more in litigation than the files would have been. A wipe that genuinely completed is reported as one.

Rebuild it next week. Image it today.

A single capture holds every answer the machine still contains — ring the freephone.