Trade secret litigation: what the forensic record can and cannot show
Misappropriation matters are decided on a narrow band of evidence — which devices were attached, which folders were opened, what a sync client uploaded, and when all of it happened relative to the departure. The examination that supports a preliminary injunction and the examination that survives a Rule 702 challenge are the same examination, run early enough.
- QUESTION
- What left, by what route, and when
- CORE ARTIFACTS
- USB · sync clients · LNK · journal
- CLOCK
- Journals and caches wrap in days
- USUAL POSTURE
- TRO / preliminary injunction
- DELIVERABLE
- Declaration, then Rule 26 report
- ROLES
- Testifying · Consulting · Neutral
In a trade secret case the forensic record normally answers three questions: which removable devices and cloud accounts touched the machine, which of the disputed files or folders were opened, and how that activity clusters around the resignation. It rarely records the copy itself. A defensible opinion states the route and the timing, identifies what would corroborate the transfer, and does not present inference as observation.
What is actually in dispute
A misappropriation claim needs the thing to have been a secret, to have been protected, and to have been acquired, used or disclosed improperly — and only the last of those is a question a forensic examiner can address.
That division matters. Whether the material qualifies as a trade secret, whether the protective measures were reasonable, and whether a covenant is enforceable are questions for the court and for counsel. What an examiner contributes is a reconstruction of conduct: which accounts touched which files, which devices were attached, what was uploaded or mailed out, and when.
These matters also run on an unusual clock. Many are filed with a motion for a temporary restraining order attached, so a declaration is needed in days rather than the months a Rule 26 schedule allows. Acquisition happens before the search protocol is settled, findings are stated on a partial record, and the report that follows months later has to be consistent with the declaration that went first. Saying less, earlier, is what makes that possible.
The four routes out
Almost every departing-employee data question resolves into one of four transfer routes, and each leaves a different record:
- Removable media. A USB drive or external disk attached to the machine. Recorded in the SYSTEM and SOFTWARE registry hives, in shortcut files that embed the volume serial number of the media, and in shellbags recording folders browsed on the volume.
- Personal cloud storage. A consumer OneDrive, Google Drive, Dropbox or Box account signed in on a company machine. The sync client writes local databases naming folders, files and sync events, and the enterprise tenant keeps its own audit trail.
- Webmail and messaging. Files attached to messages sent from a personal account, or forwarded from the corporate mailbox. The corporate side is usually the strongest record available, because mail systems log delivery rather than inferring it.
- Print, photograph and screen capture. The route that leaves the least, and is therefore the one most often overstated. Print spooler records can show a document was sent to a printer; a photograph of a screen taken on a phone leaves nothing at all on the machine.
Where the material taken is software rather than documents, the device examination establishes the route and source code review establishes what was actually copied. The two are normally run together, because neither answers the other’s question — and a matter that arrives as a trade secret claim over code frequently becomes a patent or ITC proceeding as well.
Which artifacts bear on it
The evidentiary centre of gravity in a trade secret matter is removable-media history, sync-client records, and timing. Those three do most of the work; everything else corroborates or contradicts them.
Device attachment
The USBSTOR subkey of the SYSTEM hive records the vendor, product and serial number of USB storage devices that have been attached, and related keys record when a device was first and last connected and which account mounted it. That is a specific finding: this device, this machine, this window. It is also the artifact most often asked to carry an inference it cannot support, because attachment is not transfer.
Folder and file interaction
Shellbags record that a folder was browsed through the shell, including folders on media that is no longer present. Shortcut files and jump lists record that a path was opened, and shortcuts carry the volume serial number of the device the target lived on — which is how a document opened from a specific external disk is tied back to that disk. The master file table and change journal record creations, renames and deletions at file level, and a discrepancy between the two sets of timestamps NTFS keeps is the classic signature of timestamp manipulation.
Volume, and what left the machine
SRUM, the system resource usage monitor, records bytes sent and received per application per user in hourly buckets, and is often the only local record bearing on how much data left a machine. It is a quantity, not a manifest: it can show a sync client moving several gigabytes on the Saturday before a resignation, and it cannot say what was in them.
Earlier states of the same disk
Volume shadow copies frequently hold a version of a document, a registry hive or a sync database from before it was altered or deleted, which is what makes them worth the acquisition time in a matter where someone had notice and a weekend.
What this evidence cannot establish
- That a file was copied to the device. No Windows artifact records the byte-level copy. Attachment history, shellbags, shortcuts and the change journal place a device on the machine and show a user in the folders in question. The transfer is an inference, corroborated by producing the device rather than by stacking more endpoint artifacts.
- That the account holder was the person at the keyboard. Logs record an account and a session. Attribution to a human being comes from outside the machine — badge records, video, a phone in the same building, an admission — and the report should say which, or say that none was available.
- That the files still exist, or were ever used. Nothing on the company’s side of the wire shows what a personal account holds today or what a competitor did with it. Use and disclosure are proved by discovery against the recipient, and the forensic record is what justifies seeking it.
- That nothing was taken, where the records are silent. Artifacts age out, are capped, and are switched off by configuration. A machine with no relevant history may be one on which nothing happened, or one that was never keeping the record — and which it is can usually be tested rather than assumed.
- Intent. A wiping tool installed the day before a resignation is a finding worth reporting precisely, and it is not a forensic opinion about state of mind. Deletion, encryption and the presence of a scrubbing utility bear on what a factfinder concludes; they are not themselves proof of what was destroyed or why.
The tool at can this artifact prove that? maps a proposition onto the records that bear on it and shows where the inference runs out — better done before a complaint is drafted than after a deposition.
The expert’s role and the deliverable
- Preservation, immediately. Before scope, before search terms, before anyone argues about protocol. The laptop, any device already returned, the mailbox, and the tenant audit log. The preservation deadline calculator exists for this step.
- Acquisition under write-block. Devices imaged to E01 or raw, hashed at acquisition and again at verification, with a custody form that becomes an exhibit. Where a machine cannot leave service, the alternative and its cost are recorded rather than glossed.
- Targeted analysis against the question. Device history, sync artifacts, mail, and a timeline built around the resignation date. On an injunction schedule this is deliberately narrow: a defensible declaration in days, not a complete reconstruction in months.
- Declaration. A sworn statement under 28 U.S.C. § 1746 or a state-law affidavit, stating what was examined, what was found, and — the part that carries weight later — what has not yet been examined and what that limits.
- The Rule 26(a)(2)(B) report, in due course. Complete opinions with basis and reasons, facts and data considered, exhibits, qualifications, a four-year testimony list, and compensation. Findings that cut against the retaining party are recorded the same way as the rest; an examiner who reports only helpful results is not offering an opinion.
- Rebuttal and testimony. Often the real work: testing the other examiner’s method against the same image, and either reproducing their result or saying precisely where it fails.
How the report is scoped, disclosed and defended is set out on the expert witness testimony page, and the underlying examination on the computer forensics page.
Where Rule 702 pressure falls here
Under Rule 702 as amended on December 1, 2023, the proponent must show it is more likely than not that the opinion reflects a reliable application of the method to the facts of the case. Here the challenge almost never attacks imaging or hashing. It attacks the distance between what the artifacts record and what the expert said they showed.
- The copy inference stated as observation. An opinion that attachment plus a folder listing equals a copy is the most exposed sentence in this matter type. The fix is not softer language; it is stating the route, the timing, and what would corroborate the transfer.
- Timeline reliability. A timestamp records what one source wrote, subject to time zone, clock drift, and filesystem-versus-application semantics. A timeline that has not been normalised and corroborated across sources is what an opposing expert takes apart first.
- Scope of the collection. If the personal device was never sought, or the tenant log was not preserved in time, opposing counsel will argue the opinion rests on whatever fraction of the record happened to survive. Disclosing the gap is not a weakness; discovering it on cross is.
- Opinions on secrecy, value or enforceability. Whether the material was a trade secret, and whether protection was reasonable, are not forensic findings. An expert who opines on them has a Rule 702 problem whatever the answer.
- Tool output offered without method. A parsed registry export is data. The opinion is the reasoning that connects it to the question, and a report showing the first without the second invites the argument that no method was applied to the facts of the case.
The Daubert Docket collects rulings on digital forensic testimony, including the exclusions that turned on exactly this overreach; the Daubert exposure check walks an opinion against the same failure modes before it is served, and the guide to Daubert challenges to digital evidence sets out the framework.
| RECORD | WHAT IT ESTABLISHES | WHAT IT DOES NOT ESTABLISH |
|---|---|---|
| USB device history | That a device with a specific serial was attached to this machine, by which account, and in what window | That any file moved to it. Attachment is not transfer |
| Shellbags | That a folder was browsed through the shell, including folders on media now absent | Which device the folder lived on — shellbags carry no volume serial — or whether anything was read or copied |
| Shortcut files and jump lists | That a named path was opened, and the volume serial of the media it was opened from | Whether the file was read, copied, or merely displayed; absence does not show a file was never opened |
| Sync client databases and logs | That a named account synchronised named folders and files, with local timestamps | What the receiving account holds now, or what was done with it afterwards |
| SRUM | Bytes sent per application per user, in hourly buckets — often the only local measure of volume | The content of that traffic, or which files it comprised |
| Change journal and $MFT | File-level creations, renames and deletions, and internal inconsistency where timestamps were altered | The destination of a copy. The journal is a capped circular file and may already have wrapped |
| Corporate mail logs | That a message with an attachment was delivered to an external address, with time and size | That the attachment was the disputed document, unless it was preserved and compared |
Questions counsel ask
Can a forensic expert prove our former employee took the customer list?
How quickly does this evidence disappear?
The employee used personal cloud storage, not a USB drive. Is that harder?
Do you need the employee's personal device to reach a conclusion?
Our client already collected the files themselves before calling anyone. Is that fatal?
What does the expert actually hand over at the end?
Related reading
- Employment and departing employees
The same departure, read for access and attribution rather than for exfiltration — and the account-versus-person problem in full.
- Computer forensics
Write-blocked acquisition, the artifacts an operating system keeps, and the three distinctions that keep an opinion inside what the evidence supports.
- Cloud forensics
Where the exfiltration route was a tenant rather than a device — audit logs, retention windows, and API-only collection.
- Daubert challenges to digital evidence
Rule 702 as amended in December 2023, the reliability factors, and the ways forensic opinions actually get excluded.
Devices in dispute lose evidence every time they are powered on, and tenant audit logs roll off on a schedule nobody chose. Send the matter, the venue, the departure date, and where the machines and accounts are — a conflicts check and a scoping call follow.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
Attorney advertising / expert services. This page describes forensic practice and the procedural rules that govern expert evidence in general terms. It is not legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum. Prior results do not guarantee a similar outcome.