Remote Forensics
 
Home | Contact | Search

What is Remote Forensics?

  +44 (0)845 125 4400

Using the Remote Forensics solution in the field
Using the Remote Forensics solution in the field

First responder filling in the appropriate paperwork
First responder filling in the appropriate paperwork

Remote Forensics accessible from anywhere
Remote Forensics accessible from anywhere

What does Remote Forensics do?

Forensic investigations, data recovery emergencies and e-discovery requests happen worldwide every day. Millions of pounds are spent every year in sending forensic, data recovery and e-discovery experts to remote sites in response to these requests.
The Remote Forensics architecture allows companies to dramatically reduce their investigation budgets and enable analysts to work more productively by providing a fast, secure and effective incident response framework that enforces a consistent methodology allowing analysts to remotely perform full forensic, data recovery and e-discovery tasks in remote locations at full speed using familiar forensic, e-discovery and data recovery tools.

What can be done with Remote Forensics?

Almost everything that an analyst can do in the lab can now be done remotely, quickly and easily using the Remote Forensics architecture with the added benefit of its sophisticated case management and reporting capabilities.

Although Remote Forensics is a network based architecture, no data is transferred across the network. All the work takes place at the remote end, on one of our PODs. This means that all tasks are performed at normal speeds.

In fact, using Remote Forensics means not having to stay connected to a "target" computer while transferring the forensic image or "evidence files" across a network. You can now respond to remote incidents from anywhere by:

  • connecting to the remote POD
  • triggering the imaging process (or keyword search etc)
  • closing the connection
  • return to your previous local task

So, it's possible for one person to use any tool and respond to multiple locations within minutes and trigger remote imaging, data recovery, keyword searches etc. even if the only connection to the network is a mobile phone!
...ask for more details here
 

Where are the PODs placed?

In practice, the Remote Forensics PODs are deployed into locations where there is a requirement to perform forensic analysis of digital media, e-discovery analysis or data recovery tasks.

It should be noted that there is no requirement for the POD to connect to, or be part of any organisational network. PODs can stand separate from a corporate network and still be accessed securely from any other network, making for rapid and trouble free deployment to remote or geographically variable locations
...more about PODs

Already got an enterprise solution?

Even if you have already invested in one of the "enterprise" forensic solutions, Remote Forensics can still save you time and money. Many solutions involve pre-installing a "servlet" onto each of your computers in order to gain access. This has some great benefits such as memory previews, malicious code identification etc. However, when imaging, the data has to be moved across the WAN to the analysts desk, the network connection has to be maintained in order to perform the image. Both of these factors can result in imaging taking too long.

Remote Forensics compliments the capabilities of Enterprise type solutions by providing the onsite imaging, analysis and processing speed normally only found in the lab making effective incident response possible in a reasonable timeframe.
 


 
About Us | Media | FAQ | Newsletter | Privacy