Home / Services / Investigate

Grey Fox Forensics

When something has happened and you need to know exactly what. After an incident, the evidence is the most fragile thing you own. We preserve it properly, analyse devices, accounts and logs, and give you a clear, defensible account of what happened, when, and what it touched.

What we do

Services

Incident forensics

Compromised laptops, servers and cloud accounts examined to establish entry, spread, persistence and what data was accessed.

Device & disk analysis

Forensic imaging and analysis of computers and phones — recovered files, timelines, user activity and deleted data.

Email & account compromise

Business-email-compromise and account-takeover investigations: how they got in, what they read and sent, and whether it is over.

Evidence preservation

Forensically sound collection with hashing and a documented chain of custody, so findings hold up to scrutiny.

Data recovery

Deleted, corrupted or ransomware-affected data recovered where technically possible, with honest odds given up front.

Insider & HR investigation support

Lawful, authorised examination of company devices and accounts to support disciplinary or legal processes.

Questions

Before you ask

Can you examine someone's personal phone?

Only with the lawful authority to do so — the device owner's consent, or an employer's authority over a company-owned device under its policies. We do not access devices or accounts without it.

Will the findings hold up legally?

We collect and document evidence to forensic standards so it can be relied on. Where expert-witness testimony is needed we will tell you plainly whether that is something we can provide for your matter.

How fast can you start?

Evidence degrades quickly, so early preservation matters. Tell us what happened and we will give you immediate steps to take before we begin.

Ready when you are

Email us the outcome you need. We will tell you honestly whether we are the right fit.