Computer Forensics
Computer Forensics Services in British Columbia
Forensic imaging and analysis of laptops, desktops, and servers across Windows, macOS, and Linux. Court-ready reports for BC lawyers, businesses, and private clients.

Computer forensics is the preservation, recovery, and analysis of evidence from computers and storage media. Teradrive Forensics examines laptops, desktops, external drives, USB devices, and other digital storage sources to help determine what happened, when it happened, and whether relevant files or user activity can be identified.
Our computer forensics services can include forensic disk imaging, hash verification, deleted file recovery, file system analysis, browser history review, USB device activity, logon and user activity analysis, document access timelines, and evidence preservation for litigation or investigation. Each engagement is handled with attention to chain of custody, repeatable methods, and clear reporting.
What computer forensics can recover and analyze
Computer forensics can help identify existing and deleted files, user activity, file access history, USB device connections, browser history, logon and logoff events, document timelines, and other system artifacts. What is recoverable in a given matter depends on the device, storage type, encryption, file system, and how the system has been used since the event in question.
When this service is needed
Typical scenarios where counsel and corporate clients retain us.
- Departing employee investigations
- IP and trade secret theft
- Internal fraud and policy-violation matters
- Litigation hold preservation and collection
- Expert witness engagements
- Civil and criminal proceedings
Computer forensics may be useful when digital evidence is stored on a computer, hard drive, USB device, or other storage media. Common matters include employee data theft, workplace investigations, intellectual property disputes, civil litigation, family law evidence, criminal defence support, malware or unauthorized access concerns, and recovery of deleted or missing files.
A forensic examination can help identify relevant files, user activity, access times, connected devices, browser activity, and other artifacts that may support an investigation or legal matter.
How we approach it
A defensible, repeatable process.
Intake and scope
We identify the devices, questions, timelines, and legal or investigative goals.
Preservation
Evidence is handled to protect chain of custody and reduce the risk of alteration.
Forensic imaging
Where appropriate, storage media are imaged using forensic methods and verified with cryptographic hashes.
Analysis
We examine relevant files, metadata, user activity, deleted data, browser history, USB activity, and system artifacts.
Reporting
Findings are documented in a clear report suitable for legal, business, or investigative review.
Tools we apply
Named, current, and listed in every report.
- OpenText EnCase Forensic
- Magnet AXIOM and AXIOM Cyber
- X-Ways Forensics
- Exterro FTK (formerly AccessData)
- KAPE (Kroll Artifact Parser and Extractor) for triage
- Volatility for memory analysis
- Autopsy and The Sleuth Kit for open-source verification work
Why named tools matter: opposing counsel and triers of fact often want to know exactly how an examination was performed. A vendor-neutral tool list, supported by methodology documentation, holds up better than a "proprietary process" claim.
Standards we follow
Aligned to Canadian and international guidance.
- Section 31.1 to 31.8 of the Canada Evidence Act (electronic documents)
What you receive
Deliverables built for counsel, the regulator, and the court.
- A forensic image of each examined device, hash-verified, retained on encrypted storage.
- A written examiner report covering scope, methodology, findings, exhibits, and limitations.
- An exhibit index linking each finding to its source artifact.
- An affidavit or expert affidavit if the matter requires sworn evidence.
- A chain-of-custody record from intake through archive.
- A consultation with counsel or in-house teams to walk through the report before any production.
Common questions
Computer Forensics questions from Canadian counsel and corporate clients.
What is computer forensics?
Computer forensics is the preservation, recovery, and analysis of evidence from computers, hard drives, USB devices, and other storage media. It can help identify files, user activity, deleted data, device usage, and timelines relevant to an investigation or legal matter.
Can deleted files be recovered?
Deleted files can sometimes be recovered depending on the device, file system, storage type, encryption, and whether the data has been overwritten. A forensic assessment can determine what may still be recoverable.
Can you analyze a laptop without changing the evidence?
Yes. Forensic methods are designed to preserve original evidence. Where appropriate, a forensic image is created and verified before analysis so the original device or media is protected.
How long does computer forensics take?
Timelines depend on the number of devices, storage size, encryption, urgency, and complexity of the questions being answered. Smaller matters may move quickly, while larger investigations can require staged analysis and reporting.
Is a computer forensic report admissible in court?
A forensic report may support legal proceedings when evidence is collected, preserved, analyzed, and documented using defensible methods. Admissibility depends on the matter, court, and applicable legal rules.
Computer forensics can support investigations involving employee data theft, suspected intellectual property misuse, deleted business records, unauthorized computer access, disputed document timelines, and recovery of files from laptops or external drives. Teradrive Forensics can adapt the examination scope to the matter, preserve relevant evidence, and provide clear findings for legal or business review.
Related services
Often retained alongside computer forensics.
Mobile Forensics
iOS and Android extraction including chip-off, JTAG, and ISP techniques for damaged or locked devices that conventional tools cannot read.
Explore serviceCloud Forensics
Defensible collection and analysis of Microsoft 365, Google Workspace, AWS, Slack, Teams, and Salesforce evidence under legal hold.
Explore serviceExpert Witness
Court-qualified expert witnesses delivering affidavits, expert reports, and trial testimony in Canadian civil and criminal matters.
Explore serviceHave a matter that needs computer forensics?
Tell us about it. Our team will reach out as soon as possible.
