File system records
Creation, modification, access, deletion, file paths, folder structure, document metadata, recycle bin records, and remnants of prior storage locations.
Computer forensics
A computer can preserve traces of file handling, program use, browser activity, device connections, cloud sync, and user activity long after the visible file is gone.
Operating system artifacts
Computer forensic work is rarely limited to opening a folder and looking for documents. Modern systems maintain many records that can show how files were created, accessed, modified, copied, moved, downloaded, deleted, or synchronized through cloud services.
Those records need to be compared against each other. A single timestamp, shortcut, or browser entry may be useful, but it usually does not prove a disputed allegation by itself. Stronger opinions come from patterns across source artifacts, application data, logs, metadata, and surrounding context.
Records reviewed
Creation, modification, access, deletion, file paths, folder structure, document metadata, recycle bin records, and remnants of prior storage locations.
USB device history, mounted volumes, drive labels, serial information when available, shortcut files, recent documents, and transfer indicators.
History databases, searches, downloads, cached content, cookies, sessions, extensions, private browsing remnants when available, and account activity.
Registry records, event logs, program execution, user profiles, link files, jump lists, prefetch data, account logons, and system timestamps.
Mailbox files, downloaded attachments, message stores, local caches, attachment paths, sender records, and document handling after receipt.
Local sync folders, account configuration, file version activity, conflict copies, deleted cloud content, and differences between local and cloud records.
Interpretation
Computer timestamps can reflect many events: creation, copy, download, extraction from an archive, cloud sync, software update, user access, metadata editing, or automated system activity. The same file may carry different dates depending on where the record came from.
Forensic analysis compares timestamps against file paths, user account records, application databases, operating system logs, external media history, and document metadata. That comparison is what separates a useful timeline from a list of dates.
Paths, names, dates, deletion records, and storage location.
Browser, email, office, archive, chat, and sync activity.
Logons, program execution, device connection, and service activity.
User accounts, known events, productions, and opposing claims.
Computer forensic consultation
Rune Forensics can examine computers, forensic images, file activity, deleted records, external storage use, browser artifacts, email files, and activity timelines for legal and investigative matters.
Request consultation