Technology

We built our own tools.

Most investigative firms rent the same few databases and forensic suites as everyone else. We built our own search platform, our own forensics platform, and our own reporting system, and we run every file through them.

Digital forensics

Bloodhound

Our forensics platform. It turns phone, computer, and disk evidence into findings, and records every action taken on that evidence in a custody ledger that can't be quietly altered.

Chain of custody you can check

Each evidence item is hashed when it is acquired and checked against that hash every time it is opened. Every custody event (who accessed what, when, and why) goes into an append-only ledger, and each entry is cryptographically linked to the one before it. If a record is changed, the chain breaks and the break is visible.

When a methodology is challenged, there is a signed trail from acquisition to final report.

What it reads

  • Forensic images (E01/EWF, raw dd, AFF4) and virtual disks, opened read-only
  • iOS backups, encrypted or plain, and Android filesystem and logical extractions
  • Messages, call logs, contacts, browser history, location data, media metadata, and app databases
  • Deleted records recovered from SQLite journals and unallocated space
  1. 01

    Acquire

    Register the item and hash the source before anything else touches it.

  2. 02

    Verify

    The working copy is matched to the original. A mismatch stops the case.

  3. 03

    Parse

    Records are extracted and recovered, with their location in the image kept.

  4. 04

    Correlate

    Timeline, link analysis, and hash matching across all items.

  5. 05

    Report

    Findings and the custody ledger are assembled, signed, and exported.

The tool is tested too. Bloodhound runs its parsers against known reference data and produces a signed validation report, so tool reliability is documented before anyone asks.

Reporting

A report system with rules

Our asset and locate reports are built in an in-house system that checks each report against our standards and won't print until the problems are fixed.

  • A commercial database hit is never marked "verified" on its own
  • Assessed value is labelled gross until the deed, liens, and payoffs are in hand
  • A "nothing found" result always lists what was searched
  • The collectibility verdict is on page one, with a ledger that won't total while an input is missing
  • When sources disagree, the report shows both and says which is better supported
  • The permissible purpose is recorded on the cover
Evidence capture

Exhibits that show what they claim to

Public record pages are captured by our own tool. Each capture is numbered, stamped with its source URL and time, and added to the report as an exhibit.

The tool refuses a capture if the page is an error or block page, if it is nearly empty, or if the identifier it should show (a parcel number, for example) isn't on it. That keeps a screenshot of "Access Denied" out of the exhibit list.

Security testing

Penetration testing and exposure reviews

Authorized engagements run by Kyeson Utley, an OSCP- and CEH-certified penetration tester. Scope is agreed in writing before any testing starts.

  • Penetration testing and vulnerability assessments
  • External attack surface, cloud, and web application reviews
  • Social engineering assessments
  • Findings mapped to MITRE ATT&CK, with remediation priorities
  • OSINT exposure reviews and footprint reduction for executives
  • Hardened phones and secure communications for sensitive matters

Bring us the file you can't close.

Introduce your firm and we'll explain what we would run and what the report will show.