Business Investigations

COMPUTER AND CELL PHONE DIGITAL EVIDENCE INVESTIGATIONS

Using legally accepted and qualified digital evidence forensic gathering procedures, an RNI Digital Evidence Technician is able to recover, examine and analyze data stored on computer and cell phone digital media and other selected digital electronic devices to find evidence of:

  1. Adult and Child Pornography
  2. Internet and electronic mail communications
  3. Fraud, forgery and counterfeiting
  4. Internet history and usage
  5. Marital infidelity (chat logs, internet history, e-mail, call data and text messages)
  6. Sexual harassment
  7. Other digitized data

Description of Forensic Evidence Services

Digital evidence can be recovered, examined and analyzed from desktop computers, laptop computers, network storage devices, storage media, (thumb drives, memory cards, external drives, CD/DVD), digital cameras, digital storage devices such as iPods MP-3 players, Smart and other types of cell phones, etc.

Following acceptable evidence gathering procedures, original data is examined, and a working copy of the media is prepared. Deleted materials, including erased files, folders, partitions and internet history plus call and text data are recoverable. Conversion of file fragments, file slack and unallocated disk space can be formed into searchable files.

This work is performed using industry standards tools such as a Forensic Tool Kit and Linux forensic tools such as SPADA and DEFT 6.

RNI employs a northern Michigan Digital Evidence Technician who travels throughout the lower and upper peninsulas of the state and offers three different levels of inquiries:

Level 1 is an initial or live system preview. It includes accessing the computer system in a forensically sound manner to examine media, internet history and documents and downloading this evidence to external media. A report on conclusions and findings and recommendations for further work (if necessary) is prepared. The time estimate to complete this research is approximately 3 hours plus travel time plus the cost of storage media (thumb or external drive) which can range from $25-150.

Level 2 includes the actual live system data acquisition. If after a Level 1 inquiry the findings merit further effort, this examination includes accessing the computer system in a forensically sound manner to acquire an image of the hard drive for off site evaluation of recovered or deleted data, including media files, documents, folders and internet history. These techniques are especially useful in the analysis of cell phones and other digital media devices in addition to computers. A Level 1 preview must be performed first, and then an additional 4-5 hours of examination plus travel time plus the cost of a media storage device which normally requires a hard drive equal to or larger than that contained on the device in question is required.

Level 3 involves the examination of powered down or password protected systems. Work at this most sophisticated level includes removal of the hard drive for imagining, acquiring an image in a forensically sound manner and then conducting an off site evaluation and analysis. Typical time (after Level 1 and 2 levels are completed) include 6-8 hours of recovery time plus travel plus cost of storage device.

Call or email to understand how RNI Digital Evidence Investigations can help solve your problem. Contact Charlie Rettstadt or Randy Weston at 231-347-7366 or 888-876-1010 to discuss your particular requirements. You may also send your inquiry to info@researchnorth.com


Michigan Investigator License 370120202614
Wisconsin Investigator License 15691

Copyright ©, All rights reserved
RNI, Research North and Background Checks Work are registered trademarks of Research North, Inc.
207 Michigan • Petoskey, Michigan 49770
Produced by Charlie Rettstadt