Active Incident? 24/7 Response →

For Business Owners

Forensic Investigation of a Company Device

What actually happens when a laptop or phone is examined after an incident, what the process can establish, and what it cannot.

By Quinn Varcoe, Founder & CEO, SleuthX

Why the first hour matters more than the next week

Most of what a business loses in an incident is lost before anyone calls an examiner. Not to the attacker. To ordinary, well-meant cleanup.

A device in use is a device that is changing. Every hour a suspect laptop stays in service, deleted files get overwritten by normal disk activity, access timestamps advance, and scheduled maintenance quietly discards the logs that would have shown what happened. Reimaging the machine, which is the reflex of almost every IT team, destroys the evidence completely and irreversibly.

So the useful instruction is short. Stop using the device. Do not shut it down if it is running and you can isolate it from the network instead, because memory holds things the disk does not. Do not let anyone log in to look around. Write down who has touched it and when. Then decide, unhurried, whether you need an examination at all.

What an examination actually involves

The work has a shape, and it is the same shape whether the question is theft, intrusion, or a dispute between two employees about what was said.

Acquisition

An examiner takes a bit-for-bit copy of the storage, not a copy of the files. The difference matters: a file-level copy takes what the operating system currently admits exists, while an image takes the whole volume including space the system considers free, which is where deleted material lives until it is overwritten. The original is then set aside and the analysis runs against the copy, so the evidence is never worked on directly.

Verification and chain of custody

The image is hashed, and that hash is what makes the copy defensible. Re-running it later proves the data has not changed since acquisition. Alongside it runs the chain of custody: a record of who held the device, when, and what they did with it. Chain of custody is not paperwork for its own sake. It is the thing that answers the only question an opposing expert really needs to win, which is whether anyone could have altered this between the incident and the report.

Analysis

This is where the question you asked shapes everything. An examiner reconstructs activity from artifacts the operating system creates as a side effect of normal use: records of which files were opened, which devices were attached, which accounts authenticated, what was searched for, what was deleted and when. Cloud and account logs are pulled alongside the device, because most modern activity leaves as much trace in a service provider as on the hardware.

The report

A good report states findings, the basis for each finding, and the limits of what the evidence supports. It is written to be read by someone non-technical and to survive being challenged by someone technical. Where a conclusion is probable rather than certain, it says so in those words.

What an examination cannot do

This is the part most worth reading, because it is the part that gets oversold.

How this fits an incident response

Forensic examination and incident response are related but not the same. Response is about containing an active problem. Examination is about establishing what happened, and it is what makes the answer defensible afterwards. The two overlap badly under pressure, which is why the preservation step is so often skipped.

The public frameworks are worth knowing even if you never run them yourself. NIST SP 800-86 covers integrating forensic technique into incident handling, and SP 800-61r3 is the current incident-handling guidance, having superseded the widely-cited r2 in 2025. The FTC data-breach response guide is the plainest summary of the obligations side.

When it is not worth it

Sometimes the honest answer is that an examination will not change anything. If you already know what happened, nobody disputes it, no obligation turns on the detail, and the device has been in use for weeks, then paying to confirm what you know is not a good use of money. We would rather tell you that than take the engagement.

Common questions from business owners

How long does an examination take?
Acquisition of a single laptop or phone is usually a matter of hours. Analysis is where the time goes, and it depends entirely on the question. Confirming whether a specific file was copied to a specific USB device is a narrow question and can often be answered in a day or two. Reconstructing three months of activity across a laptop, a phone, and a cloud tenant is a different order of work. An examiner who quotes you a timeline before hearing the question is guessing.
Can you tell me who did it?
Often, and with care about what the evidence actually supports. A device records account activity, not the human sitting at the keyboard. Strong cases combine device artifacts with authentication logs, badge records, and context that places a person at a machine at a time. A careful report distinguishes what is proven from what is consistent with a theory, and says which is which. Attribution stated with more confidence than the evidence carries is the fastest way to lose a case.
Will using the device destroy the evidence?
It can, and this is the single most expensive mistake a business makes. Continuing to work on a machine overwrites deleted data, updates timestamps, and can trigger cleanup routines that remove exactly the artifacts an examiner needs. The safest action once you suspect something is to stop using the device and leave it alone. Not shut down, not wiped, not handed to IT for reimaging. Just stopped and set aside.
Does this have to go to court to be worth doing?
No, and most of it does not. The same examination that would support litigation also tells you what happened, what was exposed, and whether your notification obligations are triggered. Work done to a court-admissible standard is simply work that survives being questioned later, which is worth having whether or not anyone ends up questioning it.
What do you need from us to start?
The device, physical access or a documented remote path to it, and the question you want answered. Beyond that, whatever context you already have: when you first noticed, who had access, what accounts are involved, and any logs your systems already keep. The context shortens the analysis considerably, because it narrows where to look first.

What this means for you

Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Schedule a confidential consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process. Most engagements begin within 48 hours.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 30-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management