Home // FORENSIC UNITS // DIGITAL EVIDENCE

Computer Forensics and Digital Investigation

Technical and scientific examinations of devices, systems and digital environments, with a documented chain of custody and internationally recognised methodology.

The map of this practice

Every device tells a story

Wherever there is data, there is a trace; wherever there is a trace, an examination is possible. This practice covers the full spectrum of digital environments:

Computers

Computers and storage

Desktops, laptops, servers, hard drives, SSDs and USB sticks: from system artefacts to deleted content.

Mobile

Smartphones and tablets

Android and iOS: messages, apps, location, media and the link between the content and the device.

Go to the examination page →
Chats

WhatsApp and messaging apps

Authenticity, integrity and authorship of conversations: from the challenged screenshot to hash-verified extraction.

Go to the examination page →
Embedded

Cameras, IoT and embedded systems

DVRs, IP cameras, trackers, vehicle infotainment systems, drones, smartwatches and connected devices: the evidence nobody remembers exists, and which proves decisive in accidents, employment cases and investigations.

Corporate

Databases, ERP and networks

Transactions, audit trails, connection logs and access records in corporate systems and infrastructure: who did what, and when.

Cloud

Cloud and social media

Corporate e-mail, cloud storage and social platforms, with documented and lawful collection.

Lines of digital investigation
What is investigated
Crime and fraudScams, intrusions and digital schemes, from the trace to the perpetrator
Data breachesThe origin, extent and destination of information that escaped control
IncidentsRansomware and business e-mail compromise (BEC), for insurers, regulators and litigation
Malware analysisThe behaviour, purpose and traces of malicious programs
Crypto assetsTracing of wallets, flows and exchanges, from the trace to the freezing application
OSINTOpen sources and social media, with ethical and legal limits stated up front
What secures the evidence
AuthorshipWho was behind the keyboard, demonstrated technically
PreservationThe trace frozen in time, with hash values and a documented chain of custody
CustodyMedia kept in a certified secure vault room until the case is closed
SanitisationProvable, certified destruction of data at the end of its life cycle
Due diligenceTechnical assessment of systems and assets before contracting, buying or investing
Where demand concentrates

The most requested examinations in this practice

Each of the most requested examinations has its own page, setting out the method, the reach and the limitations, all stated before any engagement.

01

Forensic extraction from mobile phones and devices

Logical, file system or physical extraction from smartphones and tablets (Android and iOS): messages, apps, location history, media with metadata, deleted content and the link between the content and the device, with hash values and sealed media.

See the examination →
02

Forensic examination of WhatsApp and app conversations

Authenticity, integrity and authorship of conversations: why a screenshot is not enough, what hash-verified extraction demonstrates and how fraud in screen captures is proven technically.

See the examination →
03

Computer and storage forensics

Laptops, desktops, servers, hard drives, SSDs and USB sticks: bit-for-bit forensic imaging, analysis of system artefacts, a timeline of use and content recovery, with the original preserved and all work carried out on copies.

04

Fraud and digital crime investigation

Scams, intrusions, misappropriation and online fraud: reconstruction of how the fraud unfolded, attribution of authorship and materialisation of the evidence for administrative or judicial accountability.

05

Data breach investigation

The origin, extent and destination of the breach: who accessed the data, when, how it left and where it went. The technical basis for incident response, regulatory notification and accountability.

06

Forensic data recovery

When the device holding the evidence is damaged, formatted or wiped: an in-house laboratory that recovers the data and delivers, along with the files, the chain of custody that supports them.

See the examination →
From device to evidence: the computer forensic examination
Method

From identification to report: the procedure that sustains the evidence

Every examination in this practice goes through the same five stages, aligned with ABNT NBR ISO/IEC 27037 and documented from first contact to delivery:

01 · IdentificationRecognition of the devices and data sources relevant to the case, definition of scope and prioritisation of what to examine first
02 · CollectionDocumented receipt with photographs, recording of identifiers and sealing; acquisition with a write blocker, bit-for-bit imaging or extraction, and SHA-256 hashing (ABNT NBR ISO/IEC 27037)
03 · ExaminationProcessing and indexing of the acquired data, recovery of deleted content and filtering of what is relevant to the scope
04 · AnalysisCorrelation of traces, timeline building, attribution of authorship and testing of competing hypotheses: the conclusion must withstand the alternative explanation
05 · ReportMethodology, tools with version numbers, findings, stated limitations and exhibits verifiable by either party

The normative basis is named, not decorative: ABNT NBR ISO/IEC 27037 for identification, collection and preservation; NIST SP 800-86 and 800-101 for the forensic process and for mobile devices; RFC 3227 for the order of volatility; and CPP, arts. 158-A to 158-F (Brazilian Code of Criminal Procedure) for the chain of custody. Every report records what was done, with what, and under which criteria, so that the method can be repeated and checked.

From media to report: the five stations of the forensic method
The laboratory

An in-house facility, from acquisition to custody

Digital forensics cannot be improvised on an ordinary laptop. Examinations take place in a dedicated laboratory, with forensic-grade equipment:

Acquisition

Write blockers and forensic duplicators

Collection and preservation in accordance with ISO/IEC 27037: the original media is read without a single bit being written to it, using hardware write blockers and forensic duplicators that generate the bit-for-bit image in a forensic container, with the hash calculated during the acquisition itself. Duplication is carried out on internationally recognised equipment, capable of processing up to 7 NVMe and 4 SATA/SAS source drives simultaneously, with output to 2 SATA/SAS and 2 NVMe drives. Every forensic examination is performed solely on the copy, known as the forensic image.

Mobile

Specialist in mobile device analysis

Mobile device extraction carried out by someone with deep knowledge of how complex this type of analysis is: Adriano Vallim served as a Cellebrite instructor for Latin America, training the law enforcement teams that operate the tool. That same experience serves both to perform extractions and to review, technically, extractions carried out by third parties.

Analysis

Dedicated processing workstations

Analysis servers separate from the acquisition workstations, able to index and correlate large volumes: in cases involving multiple devices or bulky data, the data is correlated to reveal links and to identify every trace.

Custody

Certified secure vault room

After collection and forensic indexing, the media holding the preserved data waits in a secure vault room compliant with ABNT NBR 15247 / EN 1047-2 until the case is closed, with restricted access and continuous monitoring.

The full life cycle of evidence

Preserve, hold in custody and, in the end, sanitise

Digital evidence does not end with the report. It must be born preserved, live in custody and, when the case closes, be destroyed securely. Few experts look after the entire cycle; here, it is part of the method.

Preservation

Evidence is born protected

Write blockers, bit-for-bit forensic imaging performed with hardware used by law enforcement worldwide, hash values calculated at collection and checked at verification. The original is sealed and stored in a secure vault room; every examination takes place on faithful copies.

Custody

Media kept in a secure vault room

Media held in custody is stored in a vault room certified to industry standards (ABNT NBR 15247 / EN 1047-2): protection against fire, water, gases and electromagnetic fields, controlled climate, restricted access and continuous monitoring. The evidence waits out the proceedings under bank-grade security.

Sanitisation

The secure end of life of the media

Almost no expert offers it, and every company needs it: certified forensic sanitisation of media and devices, using recognised methods and issuing a certificate of destruction. Data that must cease to exist ceases to exist provably, in compliance with the Brazilian data protection act (LGPD).

Custody of media: from collection to the secure vault room
Stated limitations

What computer forensics does not promise

Technical honesty is part of the method. Before any engagement, it is worth knowing that:

Completed cases
ANONYMISED CASE

Extraction and forensic analysis of a mobile device in a highly complex criminal investigation

Analysis of a mobile device with recovery of app data, timeline reconstruction and a report of more than 300 pages delivered in 45 days.

PUBLIC CASE

Commentary in television interviews on the seizure of devices in federal investigations

Appearances on Jornal da Record and Band explaining the technical process of forensic extraction to the public.

Frequently asked questions on this practice
What can be extracted from a mobile phone?
It depends on the model, the operating system and the condition of the device, but the reach is usually surprising: messages (including from apps), location history, photos with metadata, call records, app data and, in many scenarios, deleted content. The feasibility assessment indicates what your case allows. This examination has its own page →
Does a WhatsApp screenshot work as evidence?
A screenshot is a photograph of a screen, not the conversation: it may be accepted when it is not challenged, but it can be forged in minutes, and the Brazilian Superior Court of Justice (STJ) has already held screenshots produced without technical methodology to be inadmissible. When the conversation matters to the case, hash-verified forensic extraction is the route that withstands challenge. This subject has its own page →
Can deleted data be recovered?
Often yes, but not always: recovery depends on the space not having been overwritten and on the protections built into the system. The examination states frankly what was recovered, what was not, and why.
How is it shown that the evidence was not altered?
Through the full forensic procedure: write blockers, generation of a forensic image (a bit-for-bit copy), hash calculation at collection and at verification, and a chain of custody documented from first contact to delivery of the report. The work is always carried out on copies; the original remains preserved and sealed.
Can corporate e-mail and cloud systems be examined?
Yes, given legitimate access and proper authorisation, with documented collection and a defined scope. The lawfulness of how the material was obtained is part of the examination: badly collected evidence is tainted from birth.
Can a company examine an employee's computer?
Corporate equipment may be examined within the limits of the company's acceptable use policy and of the law. The work proceeds side by side with legal counsel so that the evidence produced is usable, rather than a liability.
What is the difference between an expert report and a technical opinion?
The expert report is the document of the expert who examines the trace directly and answers the questions to the expert; the technical opinion is the party-appointed expert's assessment of someone else's work, typical where a report already on the case file must be challenged or corroborated. Both formats are provided; the choice depends on the procedural stage of the case.
How much does a digital forensic examination cost?
There is no public price list, because no two cases are alike. Fees are built on objective criteria: the number of devices and volume of data, the technical complexity of the examination, procedural deadlines, examinations and any support required at a hearing. The workflow protects the client: a feasibility assessment at no cost, then a diagnosis and a proposal with the scope, timescale and price agreed in writing before any work begins.
How long does a digital forensic examination take?
Acquisition is usually a matter of hours; analysis depends on the volume of data and the scope, from days to weeks. The initial assessment sets a schedule by milestones, and cases with tight procedural deadlines receive prioritised triage of whatever decides the case.

See also

Forensic Extraction from Mobile Phones →   WhatsApp and Conversation Examination →   Forensic Data Recovery →   Digital Questioned Document Examination →   Expert Reports and Opinions →

The digital trace in your case needs method

The sooner the evidence is preserved, the more it will support. The feasibility assessment indicates the appropriate examination, the expected reach and the limitations, before any engagement.

Confidential consultation
Representative cases

The level of work you are engaging

Before deciding, it is worth seeing what has already come through this laboratory: cases described without identifying the parties, in the format of challenge, method and result.

See all representative cases →

The technical evidence your case requires. The authority courts respect.

Initial feasibility consultation at no cost. Reply within 24h on business days.
Request an Examination