Scientifically rigorous acquisition and analysis of digital evidence using industry-leading tools. Every investigation is documented to withstand legal scrutiny.
A digital forensics investigation answers a factual question with evidence that can be tested: who created a file, when a document was changed, whether data walked out the door with a departing employee, what a user actually did and when. The Waldrep Company handles that work for counsel nationwide, from the first scoping call through preservation, acquisition, analysis, and reporting.
The scope covers computers and laptops running Windows, macOS, or Linux, external drives and USB media, servers and network shares, cloud storage accounts, and email systems. Phones and tablets involve different tools and different artifacts, so they have their own page: mobile device forensics.
Most engagements come from attorneys in civil and criminal matters. Businesses retain us, often through counsel, to examine internal issues such as data theft or policy violations, and individuals engage us through their attorneys. Examinations are led by Eric L. Waldrep, a Magnet Certified Forensics Examiner (MCFE) with 19 years in digital forensics and 27 years in law enforcement.
Examinations use Magnet AXIOM, Cellebrite UFED, X-Ways Forensics, and other industry-standard tools, and follow NIST and SWGDE guidance for evidence handling. The lab is in Addison, Alabama. Intake is remote: devices ship in from anywhere in the country, and travel is available when testimony is needed.
From evidence intake through final reporting, the process is built to preserve the integrity of the evidence at every step.
Examination of digital media including active files, deleted data, and slack space. Findings are checked against multiple artifacts before they are reported.
Strict evidence handling procedures with documented chain of custody from intake to court presentation.
Investigation of Active Directory, Exchange, SharePoint, and enterprise storage platforms.
Detailed event timelines built from file system metadata, registry artifacts, and application logs.
Identifying data exfiltration, policy violations, and unauthorized access by employees and contractors.
Clearly written forensic reports explaining technical findings in terms that attorneys and juries can follow.
Every matter follows the same sequence, so counsel always knows where things stand and the record shows how each step was performed.
A free call to define the question, identify the devices and accounts involved, and flag deadlines. You get a written scope and estimate before any work begins.
Evidence is protected before it is examined. That can mean taking a device out of service, guidance on a litigation hold, or capturing a cloud account before it changes.
Each device is imaged behind a write blocker and the image is hashed, so the working copy can be proven identical to the original. Originals are stored, not worked on.
The examination stays on the questions in the scope: file activity, user actions, communications, timelines. Conclusions are tested against multiple artifacts, not a single log entry.
You receive a findings report in plain language with supporting exhibits, written so an attorney, a mediator, or a jury can follow the reasoning.
If the matter proceeds, declarations, deposition testimony, and trial testimony are available. Many matters resolve at the report stage and never get that far.
Forensically sound gets used loosely in this industry. In this practice it means three specific things: the original evidence is never altered, every copy is verifiable, and every step is written down.
A hardware write blocker sits between the evidence drive and the examination machine, so nothing can be written back to the original. Hashing then produces a digital fingerprint of the evidence at acquisition, and the same fingerprint is verified on the working copy. If a single bit had changed, the values would not match, and anyone can check them.
Documentation ties it together. The chain of custody log records who had the evidence, when, and why, from the moment it arrives until it is returned. Examination notes record what was done, in what order, and with which tool versions, so another examiner could retrace the work and reach the same result.
Every engagement ends with a findings report: what was examined, how, what was found, and what it means, written for a reader without a technical background. Supporting exhibits such as timelines, recovered files, and activity summaries are keyed to the report so they can be used in mediation, motion practice, or at trial.
When a sworn document is needed, findings can be prepared as a declaration or affidavit. The forensic reports and declarations page describes how those are structured.
If the matter goes further, testimony is available for depositions, hearings, and trial. Eric Waldrep has worked casework in federal and state courts. The expert witness page covers that side of the practice.
Two simple anchors, a written fee agreement before work begins, and no surprises at invoice time.
Forensic acquisition is $1,500 per device. That covers imaging, hash verification, and the chain of custody documentation that travels with the evidence.
Consulting, analysis, and review work is billed from $425/hr. If the other side has already served an expert report, a review of that report is $2,750 flat.
Testimony rates, retainer tiers, and travel terms are published on the rates page. The initial consultation is free: contact us to talk through the matter before anything is billed.
Cost, timing, cloud evidence, and what to do when the other side holds the device.
We offer a free, confidential consultation for attorneys. Call or email to get started today.
Build the same capability in-house. Our self-paced Computer Forensics Fundamentals course covers Windows, macOS, and Linux acquisition, memory forensics, and court-ready reporting.
Tell us what the matter involves and we will respond personally. Initial consultations are free, and nothing you send here is a retention.