All services

Forensics.

When data goes missing or a system is breached, two questions matter: what can be recovered, and what actually happened. We answer both. That means logical data recovery on disks and flash media, and full digital-forensic investigations, each carried out on verified copies and documented to evidentiary standard.

We respond within one business day. Reports are written for litigation and expert-witness use. Handled in confidence, no sales layer.

Recover the data. Reconstruct the story.

Two complementary disciplines, one disciplined method.

Data recovery

Logical recovery from media that is electrically sound but no longer gives up its data, after accidental deletion, a reformat, a botched partition change, or a corrupted file system. We image the device first and work only from that copy.

  • Recovery after deletion, formatting, or repartitioning
  • Rebuilding damaged or lost file systems (NTFS, exFAT, ext4, APFS…)
  • File carving when no metadata remains
  • Repair of corrupted logical sectors and structures
HDD SSD USB SD / microSD CompactFlash eMMC

Digital investigation

Post-incident forensics on workstations, servers, and storage. From the artefacts on disk and in the logs, we establish how an intrusion happened, what the attacker touched, and what left the building.

  • Timeline reconstruction across file-system and OS artefacts
  • Log and event analysis, correlated across sources
  • Evidence recovery and preservation
  • Indicator-of-compromise (IOC) extraction
  • Tracing persistence, privilege escalation, and lateral movement
Scope

We perform logical recovery on electrically healthy media, not cleanroom or chip-off hardware recovery. Straightforward physical fixes, such as re-soldering a detached USB connector, we handle in-house. Where there is genuine physical damage, we tell you up front. Full reverse engineering of any malware we uncover is available as a separate Reverse Engineering engagement.

How an investigation runs.

Evidence is preserved before it is examined, and every step is logged.

  1. Intake & scoping We agree on the media or incident, the questions to answer, and any legal or time constraints.
  2. Forensic imaging A bit-for-bit, hash-verified image. The original is sealed, and all work happens on the copy.
  3. Analysis Recovery or investigation against the agreed goals. Methodical, repeatable, and logged.
  4. Reporting Findings written up in full, from executive summary to raw technical appendix.
  5. Custody & handover The sealed original, cryptographic hashes, and a documented chain of custody are handed over with the report, ready for litigation.

A report that holds up.

Everything we find, and how we found it, written to stand up to scrutiny.

  • Executive summary in plain language
  • Full, reproducible methodology
  • Annotated timeline of events
  • Inventory of recovered data and evidence
  • IOCs: hashes, domains, IP addresses
  • Cryptographic hashes and chain of custody
  • Technical appendix with the underlying detail

Discuss a case.

Tell us what happened. We will tell you what is recoverable and what we can establish.

contact@sigreturn.com

The researcher you write to is the researcher who does the work. Who that is.