Digital Forensics Investigation | The Waldrep Company
Digital Forensics

Digital Forensics Investigation

Scientifically rigorous acquisition and analysis of digital evidence using industry-leading tools. Every investigation is documented to withstand legal scrutiny.

Digital Forensics Services for Attorneys and Businesses

A digital forensics investigation answers a factual question with evidence that can be tested: who created a file, when a document was changed, whether data walked out the door with a departing employee, what a user actually did and when. The Waldrep Company handles that work for counsel nationwide, from the first scoping call through preservation, acquisition, analysis, and reporting.

The scope covers computers and laptops running Windows, macOS, or Linux, external drives and USB media, servers and network shares, cloud storage accounts, and email systems. Phones and tablets involve different tools and different artifacts, so they have their own page: mobile device forensics.

Most engagements come from attorneys in civil and criminal matters. Businesses retain us, often through counsel, to examine internal issues such as data theft or policy violations, and individuals engage us through their attorneys. Examinations are led by Eric L. Waldrep, a Magnet Certified Forensics Examiner (MCFE) with 19 years in digital forensics and 27 years in law enforcement.

Tools, Standards, and Logistics

Examinations use Magnet AXIOM, Cellebrite UFED, X-Ways Forensics, and other industry-standard tools, and follow NIST and SWGDE guidance for evidence handling. The lab is in Addison, Alabama. Intake is remote: devices ship in from anywhere in the country, and travel is available when testimony is needed.

  • Forensically sound acquisition behind hardware write blockers
  • File system analysis and artifact recovery
  • Deleted file and data recovery
  • Email forensics and metadata analysis
  • Document authenticity and backdating questions
  • Internet and browser history examination
  • USB and external media tracking
  • Cloud storage and account activity preservation
  • Timeline reconstruction and event correlation
  • Windows, macOS, and Linux examinations
  • Findings reports, exhibits, and testimony support
19
Years in Digital Forensics
27
Years in Law Enforcement
Fed + State
Courts Qualified
100%
Chain of Custody Maintained

Forensic Analysis That Holds Up Under Questioning

From evidence intake through final reporting, the process is built to preserve the integrity of the evidence at every step.

Comprehensive Analysis

Examination of digital media including active files, deleted data, and slack space. Findings are checked against multiple artifacts before they are reported.

Chain of Custody

Strict evidence handling procedures with documented chain of custody from intake to court presentation.

Enterprise Systems

Investigation of Active Directory, Exchange, SharePoint, and enterprise storage platforms.

Timeline Reconstruction

Detailed event timelines built from file system metadata, registry artifacts, and application logs.

Insider Threat Investigations

Identifying data exfiltration, policy violations, and unauthorized access by employees and contractors.

Expert Reporting

Clearly written forensic reports explaining technical findings in terms that attorneys and juries can follow.

How a Computer Forensics Investigation Proceeds

Every matter follows the same sequence, so counsel always knows where things stand and the record shows how each step was performed.

Scoping Call

A free call to define the question, identify the devices and accounts involved, and flag deadlines. You get a written scope and estimate before any work begins.

Preservation

Evidence is protected before it is examined. That can mean taking a device out of service, guidance on a litigation hold, or capturing a cloud account before it changes.

Forensic Acquisition

Each device is imaged behind a write blocker and the image is hashed, so the working copy can be proven identical to the original. Originals are stored, not worked on.

Analysis

The examination stays on the questions in the scope: file activity, user actions, communications, timelines. Conclusions are tested against multiple artifacts, not a single log entry.

Reporting

You receive a findings report in plain language with supporting exhibits, written so an attorney, a mediator, or a jury can follow the reasoning.

Testimony When Needed

If the matter proceeds, declarations, deposition testimony, and trial testimony are available. Many matters resolve at the report stage and never get that far.

What Forensically Sound Means: Chain of Custody in Practice

Forensically sound gets used loosely in this industry. In this practice it means three specific things: the original evidence is never altered, every copy is verifiable, and every step is written down.

A hardware write blocker sits between the evidence drive and the examination machine, so nothing can be written back to the original. Hashing then produces a digital fingerprint of the evidence at acquisition, and the same fingerprint is verified on the working copy. If a single bit had changed, the values would not match, and anyone can check them.

Documentation ties it together. The chain of custody log records who had the evidence, when, and why, from the moment it arrives until it is returned. Examination notes record what was done, in what order, and with which tool versions, so another examiner could retrace the work and reach the same result.

  • Hardware write blockers on every acquisition
  • MD5 and SHA hash verification of every image
  • Chain of custody log from intake to return
  • Original media preserved, working copies analyzed
  • Access-controlled evidence storage
  • Documented tool versions and settings
  • Examination notes a second examiner can follow
  • Devices shipped with signature-tracked carriers

Digital Evidence You Can Actually Use

Every engagement ends with a findings report: what was examined, how, what was found, and what it means, written for a reader without a technical background. Supporting exhibits such as timelines, recovered files, and activity summaries are keyed to the report so they can be used in mediation, motion practice, or at trial.

When a sworn document is needed, findings can be prepared as a declaration or affidavit. The forensic reports and declarations page describes how those are structured.

If the matter goes further, testimony is available for depositions, hearings, and trial. Eric Waldrep has worked casework in federal and state courts. The expert witness page covers that side of the practice.

  • Findings report in plain language
  • Exhibits keyed to the report
  • Recovered files and extracted artifacts on request
  • Declarations and affidavits when required
  • Deposition and trial testimony
  • Review of opposing expert reports

What a Digital Forensics Investigation Costs

Two simple anchors, a written fee agreement before work begins, and no surprises at invoice time.

Forensic acquisition is $1,500 per device. That covers imaging, hash verification, and the chain of custody documentation that travels with the evidence.

Consulting, analysis, and review work is billed from $425/hr. If the other side has already served an expert report, a review of that report is $2,750 flat.

Testimony rates, retainer tiers, and travel terms are published on the rates page. The initial consultation is free: contact us to talk through the matter before anything is billed.

  • Free initial consultation
  • Written scope and estimate before work begins
  • Forensic acquisition at $1,500 per device
  • Consulting, analysis, and review from $425/hr
  • Opposing Expert Report Review at $2,750 flat
  • Full fee schedule on the rates page

Frequently Asked Questions

Cost, timing, cloud evidence, and what to do when the other side holds the device.

Forensic acquisition is $1,500 per device, which covers imaging, hash verification, and chain of custody documentation. Consulting, analysis, and review work is billed from $425/hr, and a review of an opposing expert's report is $2,750 flat. Every matter starts with a free consultation and a written estimate, and the full fee schedule is published on the rates page.
Acquisition is usually completed within a few days of receiving the device. Analysis depends on the volume of data and the questions asked: a focused examination of a single computer often takes one to two weeks, and matters with several devices or accounts take longer. Deadlines are addressed on the scoping call, and expedited handling is available when a hearing or discovery cutoff is close.
Yes. Cloud storage such as Google Drive, Dropbox, and OneDrive, hosted email in Microsoft 365 and Google Workspace, webmail, and account activity logs can all be preserved and examined with proper authorization. Cloud evidence is collected in a documented, repeatable way so the record shows exactly what was captured, when, and how.
Not if the device or account belongs to your client or your client's company, since an owner can authorize an examination of their own equipment. A court order or an agreement between the parties is typically needed when someone else controls the evidence. Counsel handles that step, and we can help draft language describing what should be preserved and produced.
That situation comes up constantly. Counsel can seek a preservation letter, an inspection protocol, or a court order that allows an expert to image the device under agreed conditions. We work under protocols that limit what is searched and who sees the results, and we can also examine data the other side has already produced in discovery.
Rarely. A single laptop, one email thread, or one departed employee is a normal starting point, and acquisition pricing is per device, so a small matter stays small. The scoping call is free, and if a forensic examination is not the right tool for the question you are asking, we will tell you that on the call.

Ready to Discuss Your Case?

We offer a free, confidential consultation for attorneys. Call or email to get started today.

Train Your Team

Build the same capability in-house. Our self-paced Computer Forensics Fundamentals course covers Windows, macOS, and Linux acquisition, memory forensics, and court-ready reporting.

View the Course →

Request a Forensic Examination

Tell us what the matter involves and we will respond personally. Initial consultations are free, and nothing you send here is a retention.

Sending this does not create an attorney-client or expert relationship, and please do not send privileged material or case evidence through this form. Prefer the phone? Call (251) 216-1164.