The File Says January. The Drive Says Otherwise.
Anyone can change the date on a document. Almost no one can change what the file system quietly recorded underneath it. That gap is where computer and hard drive forensics does its work.
Computer and hard drive forensics never examines the original device. A write-blocked, hash-verified image is captured first, and every finding — deleted files, backdated documents, exfiltrated data — is drawn from that image. This is what allows the original to be handed straight back to its owner while the analysis proceeds, and what makes the findings defensible if the opposing side challenges how the evidence was handled.
Why the Original Drive Is Never Touched
The most common way digital evidence gets thrown out in a Kenyan court isn’t a bad finding — it’s a bad process. If an examiner works directly on the original computer, opposing counsel only needs to raise one question: how do we know nothing was altered? Forensic imaging exists to remove that question entirely.
A write-blocker is a hardware device that physically permits data to be read off a drive while making it impossible to write anything back to it — not even an operating system’s routine background writes. Once attached, the examiner captures a complete, bit-for-bit copy of the drive, including deleted and unallocated space the owner can no longer see through normal use. All analysis happens on that copy.
The Imaging Chain
Five Steps Before Analysis Even Begins
This sequence is what a chain-of-custody log actually documents — and what an opposing expert will look for gaps in first.
Write-Blocker Attached
The drive is connected through hardware that permits reading only — no write commands can reach it.
Bit-for-Bit Image Captured
Every sector is copied, including deleted and unallocated space — not just visible files.
Hash Value Generated
A SHA-256 fingerprint is calculated for the original and the image, immediately after capture.
Hash Verified Match
Original and image hashes are compared — an exact match proves the copy is forensically identical.
Original Sealed & Returned
The source drive is logged and returned to its owner. All further work happens only on the verified image.
Proving a Backdated Document
A document’s visible “created” date is something almost any user can edit or spoof. What’s far harder to falsify consistently is the constellation of timestamps the file system itself maintains — commonly referred to by examiners as MACE metadata. Reconstructing a genuine timeline means comparing all four against each other and against other artifacts on the drive: recent-file lists, print spool records, backup snapshots, and system event logs from around the claimed date.
Modified
Last time the file’s content was changed
Accessed
Last time the file was opened or read
Created
When the file first appeared on this drive
Entry Modified
Last change to the file’s own metadata record
A document that was genuinely drafted on the claimed date will show these four timestamps in a pattern consistent with normal editing. A document that was written recently and then dated backward almost always shows an inconsistency somewhere in that pattern — a created date that postdates a modified date, for instance, or a file that was “created” in one location but whose surrounding system artifacts place it somewhere else entirely.
Data Exfiltration: What an Employee’s Drive Actually Reveals
When a departing employee is suspected of taking client lists, source code, or commercial records, the drive rarely has to be searched blindly — it already keeps a record of what left it.
Removable device history: the registry retains a record of every USB drive ever connected, including serial numbers and the first and last time each was plugged in.
Recently accessed files: shortcuts and jump lists reveal exactly which files were opened in the days before resignation, even if the files themselves were later deleted.
Sync and upload artifacts: local cache folders for cloud storage clients often retain evidence of what was uploaded, even after the account is logged out.
Unallocated space recovery: deleting a file removes its directory entry, not the underlying data — recoverable until that space is overwritten by new files.
Where This Sits in Kenyan Law
- Evidence Act (Cap. 80), ss. 106A–106C: the forensic image and its findings must meet the same “regular use, no unauthorised interference” standard as any other electronic record before a court will admit it.
- Computer Misuse & Cybercrimes Act 2018: unauthorised access to an employer’s system, or unauthorised copying of protected data, forms the criminal basis where exfiltration crosses into a prosecutable offence.
- Employment Act, 2007: forensic findings of exfiltration or policy breach frequently underpin the fairness of a summary dismissal, which is why documented, defensible process matters as much as the finding itself.
A Resignation Letter, Backdated by Eleven Days
A departing finance manager produced a resignation letter dated to before a disputed transaction was authorised. Forensic imaging of the laptop showed the document’s file-system creation timestamp postdated the transaction by several days, while the visible “date” field in the document text had been manually altered. Recent-file artifacts further placed the document’s drafting session on a specific afternoon, corroborated by login records for that session.
Frequently Asked Questions
Does forensic imaging require shutting down or taking away the original computer?
No. A write-blocked bit-for-bit image can usually be captured on-site, with the original device returned to service the same day. Every subsequent examination happens on the image, never the original — which is what keeps the original evidentially untouched if it’s ever challenged in court.
Can a document’s real creation date be proven if someone changed the visible date?
In most cases, yes. The visible “created” date in a file’s properties is only one of several timestamps the operating system and file system keep. Cross-referencing modified, accessed, and file-system entry timestamps — plus surrounding system artifacts — usually exposes a manual date change even when the displayed date has been altered.
If a former employee deleted files before resigning, can they still be recovered?
Frequently, yes — deletion removes the file system’s reference to the data, not the data itself, until it’s overwritten. Recovery odds depend on how much the drive has been used since deletion. This is why forensic imaging as early as possible after a suspected exfiltration is the single most important factor in recoverability.
Does it matter whether the examiner used EnCase, FTK, or Autopsy?
What matters to a Kenyan court is that the finding is independently reproducible and the chain of custody is documented — not the brand of tool. UFC cross-validates significant findings across more than one platform so that results don’t rest on a single tool’s interpretation.
Suspect a Backdated Document or Data Theft?
The moment a device is used again, potential evidence starts to erode. Free, confidential case assessment — response within 4 hours.