Remote Forensics

Garrett Discovery Inc provides remote response services over an Internet connection for many common computer forensic, investigative and data recovery tasks.


When remote response services are employed, clients will notice significant savings to both time and money as examiner travel costs and inactive time are eliminated. Urgent situations can often be addressed immediately –regardless of geographic location. We use Encase Portable, load the forensic tasks onto a dongle, and send the dongle and hard drives to you via FedEx. Once you receive these two devices they can be plugged into the target device, booted to USB, and executed. The evidence will not be changed and this service is only available to those with qualified IT staff on site. Call Garrett Discovery to discuss your situation with one of our computer forensic experts to determine if this is a viable option.

Internet History Reconstruction
Identify what websites a user has visited, determine what searches where performed, recover pictures and videos viewed online, and rebuild web pages.

Chat and Messaging Recovery
Forensic ImagingCollect full forensic images of the subject system, connected media and/or other remote systems on the destination network. Acquisitions may be “live” (capture of a running system) or “static”.

Logical Evidence Collection
Forensically collect and authenticate specific files and/or folders residing on, or accessible to, the subject system. This type of targeted collection is often used to preserve digital evidence for employment matters, domestic situations, or electronic discovery requests.

Data Scrubbing/Secure Erasure
Securely remove sensitive or confidential data by overwriting storage areas with specific data patterns. Sanitization can be performed on entire devices or can be limited to specific files, folders, or areas.

Data Recovery
Recover deleted or lost files on the subject system. The target device must be operational and must not have suffered a physical failure.

Email Recovery and Analysis
Recover, collect, and search email stored on the target system. Exchange servers can also be remotely accessed for the extraction of specific email custodians (in PST format) or the forensic collection of entire EDB files.

Keyword Searching
Search the remote system and connected media at the physical sector level for specific key terms or phrases.

Meta-data Extraction
Forensically collect files, preserve external file system meta-data, and extract internal embedded meta-data. Identify document author, dates, settings, GPS coordinates, etc.