Data forensics and image analysis
The forensic questions in a modern case often turn on a file that no one on either side quite knows how to understand. We understand it — and we tell you what it says, what it doesn’t say, and what it can’t say.
Core capabilities
Embedded event-recorder and dashcam forensics. Proprietary commercial-vehicle event-recorder file formats decoded from scratch — image, audio, accelerometer and speed streams. Recovery of deleted event files from exemplar storage media, reconstruction of missing headers, demonstration that a widely deployed format had no tamper-detection capability.
Mobile-device evidence. iPhone and iCloud production decryption and content extraction. iOS Live Photo system-file identification. Android APK reverse-engineering for copyright and trade-secret disputes.
Surveillance and dashcam video authentication. MP4 container-format and metadata analysis. Frame-timing comparison against witness statements.
Photo forensics. EXIF analysis. Camera-clock reconciliation across multiple cameras at a joint inspection. Provenance analysis of imported batches. Identification of image-editing tool signatures.
Cyber-forensic traffic tracing. Network and server traffic analysis. Metadata analysis. Infrastructure mapping. WHOIS, DNS and SSL-certificate analysis.
Cellular metadata and tower-record reconstruction
Expert-quality reconstruction of a subject’s phone activity, tower connections and estimated location envelopes. Complements police-generated CDR analysis and often catches data anomalies.
Deepfake and synthetic-media detection
Prove or disprove that a photo, audio clip or video was generated or altered by a model. Container-signature and metadata analysis, editing-tool fingerprints, and structural comparison against a manufacturer reference. Straight talk on limits: this is not always possible to prove or disprove in either direction — we tell you what our examination can and can’t support before we take the case.
Audio forensics beyond noise reduction
Spliced-audio detection. Ambient-noise sourcing. Non-AI noise reduction and filtering. Audio-timeline reconciliation. Light-and-sound-speed disparity ranging (how far was an explosion from the camera that captured it?)
PDF and document authentication
Is this contract a scanned original, a redacted copy, or a synthetic reconstruction? Font-forensic and metadata-provenance analysis of PDF and Office documents.
Cloud storage and messaging forensics
Preserve, extract and analyze Slack, Discord, WhatsApp, Teams, Google Drive, Dropbox and iCloud exports as courtroom evidence. Full audit trail. Nothing uploaded to a third-party service.
Reverse-engineering: software, firmware, embedded devices, legacy environments
A capability we have leaned on across most of our forensic casework, and one that stands on its own.
Software. C, C++, C#, Java, Kotlin, Swift, Objective-C, Python, PHP, Perl, JavaScript, Go, Rust, and older stacks like Visual Basic, Delphi, MFC, VB6 and classic Fortran. Static and dynamic analysis, decompilation, symbol recovery, and control-flow reconstruction from stripped or obfuscated binaries.
Firmware and embedded devices. ARM (Cortex-M and Cortex-A), MIPS, AVR, PIC, PowerPC. JTAG and SWD extraction where feasible. Flash-chip dumps (NOR and NAND). Real-time-OS reverse-engineering (uCOS-II, FreeRTOS and comparable). Where the device is proprietary hardware and its physical dissection is called for, we work with local partners we’ve engaged with successfully on prior matters.
Legacy software development and runtime environments. Windows 95 / 98 / NT / 2000 / XP application investigation. Silverlight, ActiveX, Java applet, Flash and Shockwave forensics. Legacy database formats — Access, Paradox, dBase, FoxPro, older SQL Server. .NET decompilation across every framework version. We keep working reference environments on hand so that a piece of evidence produced by a 25-year-old proprietary system can still be opened and understood today.
Trade-secret and software-copyright analysis
Same source-code review team that handles the largest patent litigation cases, but a different question: did this employee copy code from the previous employer? Is this app a rebuild of ours? What’s the provenance of this codebase?
