Wednesday, 21 October 2015

What is a forensic audit, and why do they require digital forensic services?

Here at DLA, some of our top clients include forensic auditors, as they require our digital forensic services for their forensic audits. But what exactly is a forensic audit and what does it mean?

Read on to explore and find out what a forensic audit is, when they are used and how they are used in court…


A forensic audit may sound like something quite exciting that you’ve probably heard on crime dramas like CSI and Law and Order, but the truth is, it is a little more boring.

A forensic audit is the process of reviewing person’s or companies financial statements to determine if they are correct and lawful. Forensic accounting is most commonly associated with tax audits, but can also be commissioned by private companies for digital forensic investigations.

So, when are forensic audits used? Forensic audits are used wherever an entity’s finances present a legal concern. For example, it is used in cased of suspected embezzlement, fraud, to investigate a spouse during divorce proceedings and so much more. This is where digital forensics comes in; our services are specifically designed to help forensic auditors in these cases.

Forensic audits are performed by a class of professionals with skills in both criminology and accounting, so they specialize in following a money trail, keeping track of fraudulent and actual balance sheets and checking for mistakes in income reports and expenditures. If they find any discrepancies, it may be the forensic auditor’s job to investigate and determine the reason for it, with the help of a digital investigator if digital evidence is needed!


How are forensic audits used in court? They are presented as evidence by a prosecutor or by a lawyer representing an interested party. Because finance is so complicated, the way a forensic auditor will describe a company’s financial position is often very precise. Because of this a prosecutor or lawyer will call an expert witness to explain the forensic audit in simpler terms in order to build a case.

Forensic audits cover a wide range of activities, and they can be a part of many different investigations, digital forensic investigations being one of them.

Wednesday, 14 October 2015

Uncover the truth about your data with cellular forensics

A few years ago, the main source of truth came from email servers. These days, work communications have elvolved and are not limited to just laptops and PCs. They have burst onto the scene with WhatsApp messages, instant messaging and mobile sharing apps.

So, where is your data going? And where is it stored?

79% of business users use SMSs or WhatsApp messaging for business communications. Those text messages can pose a significant risk.

60% of those that allowed SMSs or WhatsApp messaging had minimal or no confidence in their ability to produce messages if requested.

Outside of audits, litigation and e-discovery requests are the #1 reason digital communications data is leveraged.

Standard questions legal has for IT during discovery of data:

- Where is the backed up data stored?
- What are our retention and archival policies?
- How is the company currently backing up the data stored on laptops, PCs and mobile devices?
- Which devices (WindowsiOS, Android, Linux) are in use?
- How do we manage data belonging to ex-employees?
- How does our existing software handle and implement data privacy and confidentiality policies?
- Can we collect and preserve delete messages?
- How can I monitor messaging communications on mobile devices for adherence to regulatory mandates or internal compliance policies?

With cellular forensics, IT can:

- Give legal information about the company’s data assets
- Educate legal on all the software IT uses to manage data
- Look for opportunities for IT to identify and collect data that can facilitate repeatable collections and reduce spoilage risk.


SMSs and instant messages are increasingly an issue in investigations. But by extracting them from cellular devices can be expensive and time consuming if you don’t know what you’re doing. Contact DLA Cellular and Digital Forensics and we can follow the digital trail on your cellular or digital device to get the evidence that you need.

Wednesday, 7 October 2015

The Different phases of a Computer Forensics Investigation

Here are the following steps investigators should follow to retrieve digital evidence…


1. Secure the computer system to ensure that the equipment and data are safe. This means digital investigators must make sure that no unauthorized individual can access the computers or storage devices involved in the search.

2. Find every file on the computer system, including files that are encrypted, protected by passwords, hidden or deleted, but not yet overwritten. Digital investigators should make a copy of all the files on the system. This includes files on the computer’s hard drive or in other storage devices.

3. Recover as much deleted information as possible using applications that can detect and retrieve deleted data.

4. Reveal the contents of all hidden files with programs designed to detect the presence of hidden data.

5. Decrypt and access protected files.

6. Analyze special areas of the computer's disks, including parts that are normally inaccessible.

7. Document every step of the procedure. It's important for digital investigators to provide proof that their investigations preserved all the information on the computer system without changing or damaging it.

All these steps are incredibly important in a computer or digital forensics investigations, make sure you follow them all to ensure an effective investigation.

DLA Digital and cellular forensics can provide you with the digital evidence that you need! Let us follow the electronic trail to find and protect the evidence that you need.


Friday, 25 September 2015

How digital investigators gather evidence and solve crime with social media

Social media can be a great tool to document our daily lives, and when it comes to solving crimes, law enforcement officials and digital investigators view it as a valuable tool, too.

Who & How


An survey showed that majority use social media for several reasons:

1. Identifying people
2. Gathering evidence
3. Discovering criminal activity and locations
4. Community outreach
5. Soliciting crime tips
6. Notifying the public
7. Recruitment

People put a great amount of personal, detailed information online. Targets even brag and post illicit valuable information in reference to travel, hobbies, places visited, functions, appointments, circle of friends, family members, relationships, actions, etc.

The networks most used by law enforcement officials and digital investigators:

- Facebook
- Twitter
- Youtube

Some social media platforms can reveal more information than others.


DLA combines the experience of two seasoned investigators with both criminal and civil backgrounds with the latest technologies to acquire the digital evidence that you desire.

Wednesday, 16 September 2015

Emergency Guide: The Do’s and Do Not’s of Computer Forensic Emergencies

Read this vital guide on saving evidence in Computer Forensic Emergencies…

DO – Make detailed noted on all activities
> Collect data that would otherwise be lost by removing the power supply.
> If the device is switched on, record what is on the screen by taking photos or by making a written note of the content.
> Ensure that actions or changes made to the system are recorded. > Ask the user about the setup of the system. E.g. Passwords, usernames etc.

DO NOT – Switch on the computer
> Every time a computer is switched on data can be changed
> Make sure that the computer is switched off
> Look for activity. E.g. lights may indicate power/activity. Remove the main power source battery from laptop computers

DO – Unplug the device to ensure information cannot be overwritten
> A computer in sleep mode may be accessed remotely, allowing the alternation or deletion of files.
> Remove the power supply from the back of the computer without closing down any programs. This avoids any data being written to the hard drive with power loss.
> Remove all other connection cables leading from the computer, and make notes.

DO NOT – Continue to use the computer device
> After an incident has been established, continued usage of the computer device could prove devastating to the existing evidence.
> Deleted data can still be present on the machine, but marked as ready to over-write. Use of the computer overwrites existing data on the hard drive which could hold important evidence.

DO – Secure or seal the system in a locked cupboard or container
> By securing the computer, this can restrict any unauthorized access to the computer, which minimizes potential data loss.
> This also provides a level of protection from natural hazards or accidents that may occur around the device and cause damage to the system.

DO NOT – Let your IT department or computer specialists “have a quick look”
> Without the use of special digital forensic software and tools, tampering with the evidence can cause data to be lost or corrupt.
> Commercial “Data Recovery” software does not work for evidential purposes and could result in data loss

DO – Call us right away
DLA has grown to become a great provider of digital forensic services in Cape Town and nationwide. We pride ourselves on offering the highest quality digital forensics and delivering thorough, detailed and accurate results.  Contact us today and we can provide you with the digital evidence that you need.

Wednesday, 9 September 2015

Recover computer evidence quickly and easily!

People use their computers for almost everything; many of these things can be used against you. Hiding money, illegal activities, inappropriate emails and just about anything you can think of.

Often, if you are trying to hide something, you’ll make an effort to completely clean out your computer by deleting “everything” and reformatting. The problem is, when you contact IT support and you are told that all is lost, they probably have no idea what a digital forensic investigator can do!

The harsh truth is that the evidence is still there, waiting to be found, you just can’t see it. The only question is, do you want it recovered or not.


Many businesses that have a disgruntled employee, or feel that an employee is involved in unacceptable activities at work, may want to acquire some digital evidence, they can use a digital forensic investigator to recover all the evidence that they need.

We at DLA are pleased to provide all the evidence that you need off of a computer, cellular device, laptop or tablet. The obvious advantage that we have here at DLA is that we recover digital evidence that few others could and keep all affairs private.

Need something recovered? Don’t hesitate to give DLA a call.

Wednesday, 2 September 2015

How do I save my WhatsApp chat history?

Saving your WhatsApp messages is a relatively easy thing to do, and although it is possible to recover your WhatsApp history if it is ever lost, it’s better to just save them from the beginning to avoid problems later. Here’s how:


Your WhatsApp messages are automatically backed up and saved on your phone’s memory on a daily basis. If WhatsApp is uninstalled and you don’t want to lose any of your messages, make sure to manually back up your chats before uninstalling.

1. Open WhatsApp and go to Options > Settings > Chat History > Backup chat history.

2. Press Yes to back up your chat history.

If you are deleting and reinstalling WhatsApp, you will be asked to import your backup after you first open your new copy of WhatsApp. Simply press Restore and your chat history should begin to load.

If you need to transfer your chats from on phone to another, transfer your SD card to your new phone before installing WhatsApp. If you do not have an SD card, you will need to copy the whole “wa” folder from your old phone onto your new phone’s memory. Install WhatsApp and click on Restore when you see it, and your chat history should begin to load.

Here’s some useful technical information you may want to know about your backup:

- Backup files are saved in the “wa” folder and are called MsgStore.bak.

- Backup files are saved to both your phone’s internal memory and SD card, but only given that there’s enough space.

- Backup files are only valid for 7 days after the last save. Make sure you import your chat history before it expires!

- Backup files are phone number sensitive; they’ll only work with the same phone number.

- Backup files are saved in a format to be opened with WhatsApp. If you want to read your conversations on your computer, you can send them as .txt files from WhatsApp to your email.


DLA is based in Cape Town and combines the experience of two seasoned investigators with both criminal and civil backgrounds with the latest technologies to achieve the results that you require. We do many services, from data and WhatsApp history recovery to image and CCTV enhancement.