The Waldrep Company LLC.

The Waldrep Company LLC. Court-Ready Digital Forensics & Expert Witness Services for Legal Teams | Forensic Training

Your company's AI agent can send an email, approve a payment, or delete a file. When something goes wrong, the first que...
08/26/2026

Your company's AI agent can send an email, approve a payment, or delete a file. When something goes wrong, the first question is not what happened. It's who did it.

AI agents are now approving invoices, drafting contracts, responding to customers, and touching production systems, often under a human employee's login credentials because that is the fastest way to deploy them. That shortcut creates a problem few organizations have budgeted for: standard access logs cannot always tell you whether a person or an autonomous agent took a given action.

This is not a hypothetical. Security researchers tracking agentic AI deployments have flagged identity fluidity as one of the defining risks of 2026: agents operating under shared or borrowed credentials, actions that hide behind a human's name in the audit trail, and a single compromised agent capable of cascading through every system it touches. A breach investigation that used to start with "who logged in" now has to start with "was that login even a person."

For businesses, investigators, and corporate legal teams, this changes what incident response actually requires. Reconstructing what happened means examining agent logs, API call chains, and system-level activity alongside human access records, not instead of them, in a way that will hold up if the incident ends up in litigation or in front of a regulator.

If your organization is deploying AI agents, the time to think about forensic readiness is before an incident, not after. We can help you understand what you would need to prove, and whether you could prove it today.

Deleting a file does not erase it. It just hides it, and courts are starting to treat that difference as a legal one.On ...
08/25/2026

Deleting a file does not erase it. It just hides it, and courts are starting to treat that difference as a legal one.

On most devices, the pointer to a piece of data disappears long before the underlying data does. That is why physical extraction can recover messages, photos, and records that look permanently gone to the person who deleted them.

Courts are catching up to that reality, and not gently. In one widely reported 2025 case, Oakley v. MSG Networks, a federal court sanctioned a company after carrier records revealed 1,113 text messages that were never preserved because an auto-delete feature was left on. Litigation holds that do not specifically name Signal, WhatsApp, Google Chat, and iMessage, and confirm auto-delete has been disabled, now have a real gap in them.

For attorneys, this cuts two ways. If you represent the party who deleted something, you need to know what a forensic examiner can still recover before opposing counsel finds it first. If you represent the party seeking evidence, you need someone who can tell the difference between data that is truly gone and data that only looks that way.

That distinction is rarely obvious from the outside. It takes a forensic examination to know which one you are dealing with, and knowing early can be the difference between a strong case and a spoliation sanction.

A deepfake does not just create fake evidence. It gives real evidence a way to be dismissed.Courts are seeing more video...
08/24/2026

A deepfake does not just create fake evidence. It gives real evidence a way to be dismissed.

Courts are seeing more video, audio, and documents challenged as AI-generated than ever before. That is the visible problem. The less visible one is called the liar's dividend: once a jury knows synthetic media exists, authentic evidence becomes easier to deny.

Voice-clone fraud alone has produced documented losses from the low six figures into the tens of millions, and projections put AI-enabled fraud losses in the tens of billions nationally within the next year. Every one of those cases eventually needs an answer to the question a judge asks under Federal Rule of Evidence 901: is this authentic, and can you prove it.

Authentication is no longer a formality. It is forensic work: examining metadata, validating hash values, tracing provenance, and documenting a chain of custody that holds up under cross-examination. Generative AI can even fabricate metadata and corrupt the values used to verify a file, so the analysis has to go deeper than a surface check.

If your case involves video, audio, images, or documents whose authenticity could be challenged, in either direction, that determination should come from a court-qualified digital forensics examiner, not an assumption.

Talk to us before the question of what's real becomes the whole case.

New from The Waldrep Company: DFIR Toolkit is now live on the App Store.DFIR Toolkit is an offline field companion for d...
08/21/2026

New from The Waldrep Company: DFIR Toolkit is now live on the App Store.

DFIR Toolkit is an offline field companion for digital forensic examiners: an artifact reference, a set of forensic calculators, and encrypted case documentation, all in one app. No cloud storage. No account. No connection required.

Why it's useful: the app doesn't acquire, image, or analyze evidence. It's built to document it. Chain-of-custody and consent-to-search forms live on-device, with on-device signature capture, so your paper trail stays clean and stays defensible.

What's inside:

Evidence Forms: chain-of-custody & consent-to-search, with on-device signatures
Encrypted Case Workspace: organize matters, evidence, and notes
Artifact Reference across multiple operating systems
File Signature Database, searchable by hex, extension, or file type
Built-in calculators for timestamps, storage size, hash, and base conversions
Deterministic PDF/JSON exports (DFIR Toolkit Pro)
Fully offline, fully accessible (Dynamic Type, VoiceOver)

Free to download, with DFIR Toolkit Pro available as an optional upgrade.

Good forensic work doesn't fall apart under cross-examination because of the finding. It falls apart because the documen...
08/20/2026

Good forensic work doesn't fall apart under cross-examination because of the finding. It falls apart because the documentation couldn't back it up. That's the gap DFIR Toolkit was built to close.

It's an offline-first workspace built specifically for examiners: a case workspace to keep evidence inventory organized, versioned chain-of-custody forms, a searchable artifact reference library, and file signature lookups, covering all the unglamorous documentation work that actually determines whether a finding holds up months later in a deposition.

Offline-first isn't a buzzword here, either. It means your case data isn't dependent on a server connection or a third party's cloud to stay accessible and secure. For examiners handling sensitive casework, that matters.

You can try it free on your first case, with a Solo Pro tier for examiners who need it ongoing, and team licensing available for larger practices. It's built by someone who has had to defend his own documentation on the stand, not a generic project-management tool repackaged for forensics.

If you're an examiner or investigator, what's the part of casework documentation that eats up the most of your time? We're genuinely curious.

🛠️ Ready to see it in action? Try DFIR Toolkit free. Link in bio.

08/20/2026

Getting the data off a phone is the easiest part. Defending how you got it is the hard part.

Overcoming this problem is the foundation of all my courses. My goal is for the examiner to become court ready, not just learn how to use a tool. The Mobile Device Fundamentals Course contains fourteen modules, running in the order a real examination runs: legal authority before preservation, preservation before acquisition, acquisition before you interpret a single artifact.

Module 4 is preservation, which is where I've seen most of the damage happen, long before an examiner sees the device. Network isolation, power state, and why a phone that has been unlocked once since boot gives up far more than one that has not.

Module 12 is the part most training lacks. Writing the report, stating your acquisition method and its limits, and defending both from the stand.

Mobile Device Forensics Fundamentals is 14 modules, 21 lessons, 10 CPE hours and 12 months of access, with the reference library and bench checklists included. The four-day classroom version of this same course runs $2,595 a seat. Self-paced, it is $497 through September 30. From October 1 it is $697.

If mobile is not the only kind of evidence that lands on your bench, All-Access is all four online courses for $2,997 instead of $4,488 separately: computer, mobile, drone and open source. 86 CPE hours, and four separate certificates rather than one combined one. That $2,997 does not move on October 1, so the gap only gets wider.

Agencies: 25% off at 5 or more seats, purchase orders and net-30 accepted. A written quote issued before September 30 holds its price.

Course: thewaldrepcompany.com/courses/mobile-device-forensics/
All four: thewaldrepcompany.com/courses/all-access/

When you hire an expert witness, it's easy to assume one person will handle the whole case. That's not always how it wor...
08/19/2026

When you hire an expert witness, it's easy to assume one person will handle the whole case. That's not always how it works, since some firms pass evidence between whichever examiner is available at each stage.

At The Waldrep Company, one qualified examiner handles a case from intake through testimony: reviewing the evidence, performing the forensic analysis, and then standing behind the findings in a deposition or on the stand. No hand-off to a technician who never has to defend the work, and no rotating cast of analysts across a single case file.

That continuity matters more than it might seem. An examiner who did the analysis themselves can answer the harder cross-examination questions, the ones that go beyond what's written in the report. It's part of what supports a track record of 200+ cases handled without a single disqualification as an expert witness.

If you're evaluating a digital forensics expert for an upcoming case, it's worth asking how many people will actually touch your evidence. The answer says a lot about what you're getting.

📞 Have a case that needs one accountable expert from start to finish? Schedule a free consultation with The Waldrep Company.

Most people assume "deleted" means "gone." In digital forensics, it usually just means "hidden from view." When a text m...
08/18/2026

Most people assume "deleted" means "gone." In digital forensics, it usually just means "hidden from view." When a text message is deleted, the data typically stays in the phone's storage until new activity overwrites it, which can happen within days of normal use.

That timing is exactly why early action matters. If a deleted message could matter to a legal case, such as a custody dispute, a workplace investigation, or an accident claim, the device needs to stop being used, and the search for a qualified examiner needs to start immediately. Waiting a week to "figure out next steps" can be the difference between recoverable evidence and data that's permanently overwritten.

It's also worth clearing up a common myth: carriers are not a backup plan. They typically retain very little message content, and only for a short window. What they can usually provide is metadata (numbers and timestamps), not the message itself.

Recovering that data in a way that actually holds up in court takes more than "restoring a text." It requires documented acquisition, verification, and a properly qualified examiner's report.

Have you ever needed to recover something you thought was permanently deleted? We'd be curious to hear how it turned out.

📞 If a deleted message might matter to your case, don't wait. Schedule a free consultation with The Waldrep Company today.

08/09/2026

I’ve spent 27 years working with Law Enforcement. The cases that kept me up were never the complicated ones.

They were the ones where we already had the evidence and nobody in the building could open it.

A phone goes into a queue. A laptop waits months for a lab slot. A drone sits in property because the one person who might have known what to pull off it does not work there anymore.

That is not a technology problem. The tools exist and they work. It is a coverage problem. If departments certify one person in one discipline, and then the case walks in with four kinds of evidence in the same box, what do you do?

I have now watched this from both sides. Several years carrying cases myself, then several more years as a cyber mentor overseas for the State Department’s Antiterrorism Assistance program. Different countries, different agencies, same gap every time.

The fix is not glamorous. It is one examiner who can competently work a computer, a phone, a drone, and an open source trail, and who can explain all four on the stand without coming apart on cross.

That is what I built the online curriculum around.

Take it further: all four courses in one enrollment. Details in the comments.

07/28/2026

Prefetch shows Windows prepared an executable for launch. It does not show who was sitting at the keyboard.

That distinction is the whole reason the artifact reference in DFIR Toolkit exists. Every entry states what the artifact CAN SUPPORT and, on the same card, what it DOES NOT PROVE, with sources cited. You read both before you write the sentence that ends up in a report.

It is not an examination tool. It does not acquire, parse, carve or analyze anything. It documents the work around the exam: case workspace, evidence forms, calculators, artifact and file signature reference, field guides, standards library. Offline-first, so it still works in a lab with no network and in a vehicle with no signal.

Case records stay in a device-local encrypted vault, AES-GCM, key derived from your passphrase. No evidence is uploaded. The hosted layer holds identity and billing only. No server-side recovery either, which is the honest cost of that design.

Public demo, synthetic data, no signup. Link in bio.

Address

118 Margaret Street
Addison, AL
35540

Alerts

Be the first to know and let us send you an email when The Waldrep Company LLC. posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to The Waldrep Company LLC.:

Shortcuts

Share