Data forensics and image analysis

The forensic questions in a modern case often turn on a file that no one on either side quite knows how to understand. We understand it — and we tell you what it says, what it doesn’t say, and what it can’t say.

Placeholder for data forensics heroIllustrative image — actual case work is confidential.

Core capabilities

Embedded event-recorder and dashcam forensics. Proprietary commercial-vehicle event-recorder file formats decoded from scratch — image, audio, accelerometer and speed streams. Recovery of deleted event files from exemplar storage media, reconstruction of missing headers, demonstration that a widely deployed format had no tamper-detection capability.

Mobile-device evidence. iPhone and iCloud production decryption and content extraction. iOS Live Photo system-file identification. Android APK reverse-engineering for copyright and trade-secret disputes.

Surveillance and dashcam video authentication. MP4 container-format and metadata analysis. Frame-timing comparison against witness statements.

Photo forensics. EXIF analysis. Camera-clock reconciliation across multiple cameras at a joint inspection. Provenance analysis of imported batches. Identification of image-editing tool signatures.

Cyber-forensic traffic tracing. Network and server traffic analysis. Metadata analysis. Infrastructure mapping. WHOIS, DNS and SSL-certificate analysis.

Cellular metadata and tower-record reconstruction

Expert-quality reconstruction of a subject’s phone activity, tower connections and estimated location envelopes. Complements police-generated CDR analysis and often catches data anomalies.

Deepfake and synthetic-media detection

Prove or disprove that a photo, audio clip or video was generated or altered by a model. Container-signature and metadata analysis, editing-tool fingerprints, and structural comparison against a manufacturer reference. Straight talk on limits: this is not always possible to prove or disprove in either direction — we tell you what our examination can and can’t support before we take the case.

Audio forensics beyond noise reduction

Spliced-audio detection. Ambient-noise sourcing. Non-AI noise reduction and filtering. Audio-timeline reconciliation. Light-and-sound-speed disparity ranging (how far was an explosion from the camera that captured it?)

PDF and document authentication

Is this contract a scanned original, a redacted copy, or a synthetic reconstruction? Font-forensic and metadata-provenance analysis of PDF and Office documents.

Cloud storage and messaging forensics

Preserve, extract and analyze Slack, Discord, WhatsApp, Teams, Google Drive, Dropbox and iCloud exports as courtroom evidence. Full audit trail. Nothing uploaded to a third-party service.

Reverse-engineering: software, firmware, embedded devices, legacy environments

A capability we have leaned on across most of our forensic casework, and one that stands on its own.

Software. C, C++, C#, Java, Kotlin, Swift, Objective-C, Python, PHP, Perl, JavaScript, Go, Rust, and older stacks like Visual Basic, Delphi, MFC, VB6 and classic Fortran. Static and dynamic analysis, decompilation, symbol recovery, and control-flow reconstruction from stripped or obfuscated binaries.

Firmware and embedded devices. ARM (Cortex-M and Cortex-A), MIPS, AVR, PIC, PowerPC. JTAG and SWD extraction where feasible. Flash-chip dumps (NOR and NAND). Real-time-OS reverse-engineering (uCOS-II, FreeRTOS and comparable). Where the device is proprietary hardware and its physical dissection is called for, we work with local partners we’ve engaged with successfully on prior matters.

Legacy software development and runtime environments. Windows 95 / 98 / NT / 2000 / XP application investigation. Silverlight, ActiveX, Java applet, Flash and Shockwave forensics. Legacy database formats — Access, Paradox, dBase, FoxPro, older SQL Server. .NET decompilation across every framework version. We keep working reference environments on hand so that a piece of evidence produced by a 25-year-old proprietary system can still be opened and understood today.

Trade-secret and software-copyright analysis

Same source-code review team that handles the largest patent litigation cases, but a different question: did this employee copy code from the previous employer? Is this app a rebuild of ours? What’s the provenance of this codebase?

Daubert and admissibility. Where the analysis is going to a jury, we build to it. Findings are backed by a written methodology, a preserved chain of custody, and an explicit statement of what the analysis can and cannot support. We do not use “AI enhancement” on visual evidence in a form that fabricates pixels.

Submit a case

Scroll to top
Skip to content