SKIP TO CONTENT
MATTER TYPE / TRADE SECRET

Trade secret litigation: what the forensic record can and cannot show

Misappropriation matters are decided on a narrow band of evidence — which devices were attached, which folders were opened, what a sync client uploaded, and when all of it happened relative to the departure. The examination that supports a preliminary injunction and the examination that survives a Rule 702 challenge are the same examination, run early enough.

QUESTION
What left, by what route, and when
CORE ARTIFACTS
USB · sync clients · LNK · journal
CLOCK
Journals and caches wrap in days
USUAL POSTURE
TRO / preliminary injunction
DELIVERABLE
Declaration, then Rule 26 report
ROLES
Testifying · Consulting · Neutral
IN SHORT

In a trade secret case the forensic record normally answers three questions: which removable devices and cloud accounts touched the machine, which of the disputed files or folders were opened, and how that activity clusters around the resignation. It rarely records the copy itself. A defensible opinion states the route and the timing, identifies what would corroborate the transfer, and does not present inference as observation.

What is actually in dispute

A misappropriation claim needs the thing to have been a secret, to have been protected, and to have been acquired, used or disclosed improperly — and only the last of those is a question a forensic examiner can address.

That division matters. Whether the material qualifies as a trade secret, whether the protective measures were reasonable, and whether a covenant is enforceable are questions for the court and for counsel. What an examiner contributes is a reconstruction of conduct: which accounts touched which files, which devices were attached, what was uploaded or mailed out, and when.

These matters also run on an unusual clock. Many are filed with a motion for a temporary restraining order attached, so a declaration is needed in days rather than the months a Rule 26 schedule allows. Acquisition happens before the search protocol is settled, findings are stated on a partial record, and the report that follows months later has to be consistent with the declaration that went first. Saying less, earlier, is what makes that possible.

The four routes out

Almost every departing-employee data question resolves into one of four transfer routes, and each leaves a different record:

  • Removable media. A USB drive or external disk attached to the machine. Recorded in the SYSTEM and SOFTWARE registry hives, in shortcut files that embed the volume serial number of the media, and in shellbags recording folders browsed on the volume.
  • Personal cloud storage. A consumer OneDrive, Google Drive, Dropbox or Box account signed in on a company machine. The sync client writes local databases naming folders, files and sync events, and the enterprise tenant keeps its own audit trail.
  • Webmail and messaging. Files attached to messages sent from a personal account, or forwarded from the corporate mailbox. The corporate side is usually the strongest record available, because mail systems log delivery rather than inferring it.
  • Print, photograph and screen capture. The route that leaves the least, and is therefore the one most often overstated. Print spooler records can show a document was sent to a printer; a photograph of a screen taken on a phone leaves nothing at all on the machine.

Where the material taken is software rather than documents, the device examination establishes the route and source code review establishes what was actually copied. The two are normally run together, because neither answers the other’s question — and a matter that arrives as a trade secret claim over code frequently becomes a patent or ITC proceeding as well.

Which artifacts bear on it

The evidentiary centre of gravity in a trade secret matter is removable-media history, sync-client records, and timing. Those three do most of the work; everything else corroborates or contradicts them.

Device attachment

The USBSTOR subkey of the SYSTEM hive records the vendor, product and serial number of USB storage devices that have been attached, and related keys record when a device was first and last connected and which account mounted it. That is a specific finding: this device, this machine, this window. It is also the artifact most often asked to carry an inference it cannot support, because attachment is not transfer.

Folder and file interaction

Shellbags record that a folder was browsed through the shell, including folders on media that is no longer present. Shortcut files and jump lists record that a path was opened, and shortcuts carry the volume serial number of the device the target lived on — which is how a document opened from a specific external disk is tied back to that disk. The master file table and change journal record creations, renames and deletions at file level, and a discrepancy between the two sets of timestamps NTFS keeps is the classic signature of timestamp manipulation.

Volume, and what left the machine

SRUM, the system resource usage monitor, records bytes sent and received per application per user in hourly buckets, and is often the only local record bearing on how much data left a machine. It is a quantity, not a manifest: it can show a sync client moving several gigabytes on the Saturday before a resignation, and it cannot say what was in them.

Earlier states of the same disk

Volume shadow copies frequently hold a version of a document, a registry hive or a sync database from before it was altered or deleted, which is what makes them worth the acquisition time in a matter where someone had notice and a weekend.

Limits of proof

What this evidence cannot establish

  • That a file was copied to the device. No Windows artifact records the byte-level copy. Attachment history, shellbags, shortcuts and the change journal place a device on the machine and show a user in the folders in question. The transfer is an inference, corroborated by producing the device rather than by stacking more endpoint artifacts.
  • That the account holder was the person at the keyboard. Logs record an account and a session. Attribution to a human being comes from outside the machine — badge records, video, a phone in the same building, an admission — and the report should say which, or say that none was available.
  • That the files still exist, or were ever used. Nothing on the company’s side of the wire shows what a personal account holds today or what a competitor did with it. Use and disclosure are proved by discovery against the recipient, and the forensic record is what justifies seeking it.
  • That nothing was taken, where the records are silent. Artifacts age out, are capped, and are switched off by configuration. A machine with no relevant history may be one on which nothing happened, or one that was never keeping the record — and which it is can usually be tested rather than assumed.
  • Intent. A wiping tool installed the day before a resignation is a finding worth reporting precisely, and it is not a forensic opinion about state of mind. Deletion, encryption and the presence of a scrubbing utility bear on what a factfinder concludes; they are not themselves proof of what was destroyed or why.

The tool at can this artifact prove that? maps a proposition onto the records that bear on it and shows where the inference runs out — better done before a complaint is drafted than after a deposition.

The expert’s role and the deliverable

  1. Preservation, immediately. Before scope, before search terms, before anyone argues about protocol. The laptop, any device already returned, the mailbox, and the tenant audit log. The preservation deadline calculator exists for this step.
  2. Acquisition under write-block. Devices imaged to E01 or raw, hashed at acquisition and again at verification, with a custody form that becomes an exhibit. Where a machine cannot leave service, the alternative and its cost are recorded rather than glossed.
  3. Targeted analysis against the question. Device history, sync artifacts, mail, and a timeline built around the resignation date. On an injunction schedule this is deliberately narrow: a defensible declaration in days, not a complete reconstruction in months.
  4. Declaration. A sworn statement under 28 U.S.C. § 1746 or a state-law affidavit, stating what was examined, what was found, and — the part that carries weight later — what has not yet been examined and what that limits.
  5. The Rule 26(a)(2)(B) report, in due course. Complete opinions with basis and reasons, facts and data considered, exhibits, qualifications, a four-year testimony list, and compensation. Findings that cut against the retaining party are recorded the same way as the rest; an examiner who reports only helpful results is not offering an opinion.
  6. Rebuttal and testimony. Often the real work: testing the other examiner’s method against the same image, and either reproducing their result or saying precisely where it fails.

How the report is scoped, disclosed and defended is set out on the expert witness testimony page, and the underlying examination on the computer forensics page.

Where Rule 702 pressure falls here

Under Rule 702 as amended on December 1, 2023, the proponent must show it is more likely than not that the opinion reflects a reliable application of the method to the facts of the case. Here the challenge almost never attacks imaging or hashing. It attacks the distance between what the artifacts record and what the expert said they showed.

  • The copy inference stated as observation. An opinion that attachment plus a folder listing equals a copy is the most exposed sentence in this matter type. The fix is not softer language; it is stating the route, the timing, and what would corroborate the transfer.
  • Timeline reliability. A timestamp records what one source wrote, subject to time zone, clock drift, and filesystem-versus-application semantics. A timeline that has not been normalised and corroborated across sources is what an opposing expert takes apart first.
  • Scope of the collection. If the personal device was never sought, or the tenant log was not preserved in time, opposing counsel will argue the opinion rests on whatever fraction of the record happened to survive. Disclosing the gap is not a weakness; discovering it on cross is.
  • Opinions on secrecy, value or enforceability. Whether the material was a trade secret, and whether protection was reasonable, are not forensic findings. An expert who opines on them has a Rule 702 problem whatever the answer.
  • Tool output offered without method. A parsed registry export is data. The opinion is the reasoning that connects it to the question, and a report showing the first without the second invites the argument that no method was applied to the facts of the case.

The Daubert Docket collects rulings on digital forensic testimony, including the exclusions that turned on exactly this overreach; the Daubert exposure check walks an opinion against the same failure modes before it is served, and the guide to Daubert challenges to digital evidence sets out the framework.

RECORDWHAT IT ESTABLISHESWHAT IT DOES NOT ESTABLISH
USB device historyThat a device with a specific serial was attached to this machine, by which account, and in what windowThat any file moved to it. Attachment is not transfer
ShellbagsThat a folder was browsed through the shell, including folders on media now absentWhich device the folder lived on — shellbags carry no volume serial — or whether anything was read or copied
Shortcut files and jump listsThat a named path was opened, and the volume serial of the media it was opened fromWhether the file was read, copied, or merely displayed; absence does not show a file was never opened
Sync client databases and logsThat a named account synchronised named folders and files, with local timestampsWhat the receiving account holds now, or what was done with it afterwards
SRUMBytes sent per application per user, in hourly buckets — often the only local measure of volumeThe content of that traffic, or which files it comprised
Change journal and $MFTFile-level creations, renames and deletions, and internal inconsistency where timestamps were alteredThe destination of a copy. The journal is a capped circular file and may already have wrapped
Corporate mail logsThat a message with an attachment was delivered to an external address, with time and sizeThat the attachment was the disputed document, unless it was preserved and compared
The right-hand column is the one that decides Rule 702 motions in this matter type. Each record above has its own page under /artifacts setting out retention, failure modes, and how a finding drawn from it is attacked.

Questions counsel ask

Can a forensic expert prove our former employee took the customer list?

Usually the expert can prove a great deal short of that. Registry records show which removable devices were attached and when; shellbags and jump lists show folders opened on those volumes; shortcut files carry the volume serial number of the media a document was opened from; and sync client databases record what a personal cloud account uploaded. Together those place a specific device on the machine and date the activity against the resignation. What no Windows artifact records is the byte-level copy itself, so the honest formulation is what the artifacts show plus what would corroborate them.

How quickly does this evidence disappear?

Faster than most matters move. Prefetch is capped and rolls over on a busy machine within weeks. The change journal is a fixed-size circular file that can wrap in days. Cloud tenant audit logs are retained on a schedule the tenant set years ago. Shadow copies are deleted as space is reclaimed, and a device left in service overwrites its own history. Preservation is the step that decides what is available later, and it comes before any decision about whom to retain.

The employee used personal cloud storage, not a USB drive. Is that harder?

It is different rather than harder, and often better documented. Sync clients for OneDrive, Google Drive, Dropbox and Box write local databases and logs naming folders, files and sync events, and the enterprise tenant keeps its own audit trail. Browser artifacts show a personal account being reached from a company machine. What the endpoint cannot do is prove what that personal account holds now; the forensic record is what supports seeking it in discovery.

Do you need the employee's personal device to reach a conclusion?

Not always. A company-side examination can establish that data was staged, that a device with a particular serial was attached, or that a personal account received uploads. Producing the receiving device moves a finding from strong inference to direct corroboration, because the material can then be located and compared. Where it cannot be obtained, the report says which conclusions would have been testable with it and which are unaffected.

Our client already collected the files themselves before calling anyone. Is that fatal?

It is a problem to address early rather than a fatal one. Self-collection by drag-and-drop overwrites last-accessed times and drops the original filesystem metadata, so it damages the evidence about the evidence rather than the documents themselves. The usual course is to preserve the source device properly now, examine it alongside the self-collected set, and document the difference so the gap is disclosed by your side rather than found on cross.

What does the expert actually hand over at the end?

In federal court, a written report meeting Rule 26(a)(2)(B): every opinion with its basis and reasons, the facts and data considered, exhibits, qualifications, a four-year testimony list, and compensation. On an expedited injunction schedule the instrument is more often a declaration with the same discipline behind it. Either way each assertion traces to a named artifact, and an opposing expert working from the same image can reproduce it or say where it fails.
  • Employment and departing employees

    The same departure, read for access and attribution rather than for exfiltration — and the account-versus-person problem in full.

  • Computer forensics

    Write-blocked acquisition, the artifacts an operating system keeps, and the three distinctions that keep an opinion inside what the evidence supports.

  • Cloud forensics

    Where the exfiltration route was a tenant rather than a device — audit logs, retention windows, and API-only collection.

  • Daubert challenges to digital evidence

    Rule 702 as amended in December 2023, the reliability factors, and the ways forensic opinions actually get excluded.

ENGAGE AN EXPERT ON A TRADE SECRET MATTER

Devices in dispute lose evidence every time they are powered on, and tenant audit logs roll off on a schedule nobody chose. Send the matter, the venue, the departure date, and where the machines and accounts are — a conflicts check and a scoping call follow.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

Attorney advertising / expert services. This page describes forensic practice and the procedural rules that govern expert evidence in general terms. It is not legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum. Prior results do not guarantee a similar outcome.