You are on page 1of 2

Dear All,

 Date: 27 June 2022

Proposal for Laptop Forensics 


Scope of work:

 Data File Recovery/Analysis:  Yes we can do Data recovery/ Analysis.

    Keywords search: We can perform keywords searching i.e. some keywords would be given & we
will trace the keywords if present if present in any file, folders.  

    Apart from above the below mentioned details will be tried to be recovered. 

1)The number of USB pendrives that were connected to the laptop


2) Files/Folders which were accessed or opened during the last one month
3) Email ids that were accessed from that laptop ( Including passwords if possible)
4) Browser history
5) Software's that were installed or updated during the last one month
6) Data recovery of any files which are deleted.

    Proposal one:  Duration 1-2 days 

Normal forensics (report is only for company knowledge & cannot be used in the court of law) :

Rs 10,000/- per computer ( can be done via team-viewer or sending a resource)

 Disclaimer: The report provided by us can be used only for internal purpose & cannot be used for
any legal purpose. The report would be a summary report & not a detailed description would be
provided, it would however contain all the technical information as mentioned above that we will
recover from the laptop

Prerequisite: Before the starting the activity, Please do the needful:-

1. Anti-Virus should be disabled 

2. Admin rights to run software’s 

 
Proposal 2: Duration 10-12 days

Official Forensics: Rs 35000/- per computer (Imaging & data analysis) Travelling & accommodation
extra

It will include imaging plus recovery of evidences using commercial software (Encase or Forensics
toolkit).

  Prerequisite: Before the starting the activity, Please do the needful:-

1) We will need an extra hard disk( double the size of the original hard disk which is to be imaged)

2) Imaging will take one day, loading the image will take 2-3 days, analysis one day this is the general
time frame for a single hdd analysis

3) Please provide good configuration desktop/laptop where we can load the image (preferred i5 or
i7 with minimum 8-16 gb ram), if configuration is low imaging will take more time.

Please let me know if you have any query.

  

Limitations:

 Identify Data Theft: It is difficult to ascertain which files where transferred unless we have access to
the Email accounts or pen drives. So we can do time line forensics , at the most we can ascertain
which pen drives were connected , which email accounts were opened & which files were accessed
on the computer & try & recover as many files as possible from the laptop.

You might also like