Computer forensics

Computer examinations reconstruct activity, not just files.

A computer can preserve traces of file handling, program use, browser activity, device connections, cloud sync, and user activity long after the visible file is gone.

Operating system artifacts

What a computer may remember

Computer forensic work is rarely limited to opening a folder and looking for documents. Modern systems maintain many records that can show how files were created, accessed, modified, copied, moved, downloaded, deleted, or synchronized through cloud services.

Those records need to be compared against each other. A single timestamp, shortcut, or browser entry may be useful, but it usually does not prove a disputed allegation by itself. Stronger opinions come from patterns across source artifacts, application data, logs, metadata, and surrounding context.

Records reviewed

Activity can appear in more than one place.

Files

File system records

Creation, modification, access, deletion, file paths, folder structure, document metadata, recycle bin records, and remnants of prior storage locations.

Devices

External storage

USB device history, mounted volumes, drive labels, serial information when available, shortcut files, recent documents, and transfer indicators.

Web

Browser activity

History databases, searches, downloads, cached content, cookies, sessions, extensions, private browsing remnants when available, and account activity.

System

Windows and OS artifacts

Registry records, event logs, program execution, user profiles, link files, jump lists, prefetch data, account logons, and system timestamps.

Email

Email and attachments

Mailbox files, downloaded attachments, message stores, local caches, attachment paths, sender records, and document handling after receipt.

Cloud

Sync folders and accounts

Local sync folders, account configuration, file version activity, conflict copies, deleted cloud content, and differences between local and cloud records.

Interpretation

A timestamp is a clue, not a conclusion.

Computer timestamps can reflect many events: creation, copy, download, extraction from an archive, cloud sync, software update, user access, metadata editing, or automated system activity. The same file may carry different dates depending on where the record came from.

Forensic analysis compares timestamps against file paths, user account records, application databases, operating system logs, external media history, and document metadata. That comparison is what separates a useful timeline from a list of dates.

Timeline sources

  1. File system

    Paths, names, dates, deletion records, and storage location.

  2. Application records

    Browser, email, office, archive, chat, and sync activity.

  3. System logs

    Logons, program execution, device connection, and service activity.

  4. Context

    User accounts, known events, productions, and opposing claims.

Computer forensic consultation

Need to understand what a computer actually shows?

Rune Forensics can examine computers, forensic images, file activity, deleted records, external storage use, browser artifacts, email files, and activity timelines for legal and investigative matters.

Request consultation