Field report: executive endpoint investigation
Onsite investigation of a director’s laptop following reports of abnormal startup behaviour and suspected malware. The initial objective was to preserve the installed storage, establish a trusted boot environment and acquire evidence without starting the resident operating system.
Assignment record
| DEVICE | Executive-class 14-inch laptop / integrated M.2 storage |
|---|---|
| REPORTED FAULT | Unexpected pre-boot messages, repeated startup repair and suspected virus activity |
| INITIAL CONTROL | Device isolated from wired, wireless and mobile networks |
| REQUESTED OUTCOME | Trusted offline boot, forensic acquisition and malware assessment |
| ATTENDANCE | Director’s office / mobile technical workshop |
08:36 — Receipt and initial condition
The laptop was received powered off with its AC adapter and no other removable media. The director reported that it had displayed an unfamiliar message before Windows loaded, restarted twice and entered automatic repair. A local antivirus notification had been seen during the previous session but its text had not been recorded. The device was then shut down by holding the power button.
No further start from the internal drive was authorised onsite. Network interfaces were isolated and the external condition, asset number, port state and visible tamper indicators were photographed. The symptoms were not sufficient to confirm malware, but bootloader interference remained within scope and required the internal operating system to be treated as untrusted.
09:02 — External USB boot attempt
A write-protected recovery drive containing the approved acquisition environment was connected before power-on. The firmware setup recognised a generic USB storage device in its peripheral inventory but did not expose it as a boot option. Disabling fast boot, selecting the temporary boot menu and recreating the drive in both UEFI and legacy-compatible layouts produced the same result.
Secure Boot state and firmware settings were recorded before each change and returned to their original values after testing. No firmware password was present. The USB ports remained usable inside the firmware diagnostics, indicating that the failure was limited to boot-device enumeration rather than total port loss.
09:47 — Secondary SATA boot path
To avoid the USB boot path, a known-good SATA recovery drive was installed in an optical-bay adapter. This method normally presents a secondary disk through the laptop’s internal SATA controller while leaving the primary storage untouched. The adapter received power, but neither the firmware information page nor the temporary boot menu listed the drive.
The same recovery drive and adapter were verified in the mobile workshop test system. Inspection of the laptop’s optical-bay connector found no obvious contamination or displaced contact. Firmware diagnostics reported the bay as present but returned no device identity, so the secondary SATA method was withdrawn.
10:31 — Optical-disc recovery attempt
A signed recovery image was written to CD-R and presented as CD-ROM boot media, providing a third independent boot source. The installed optical drive accepted the disc, attempted to seek and then returned to the firmware menu without reading its boot record. Two known-good diagnostic discs produced repeated seek noise and the same outcome.
The drive’s emergency eject and mechanical loading functions operated, but it could not read a directory or complete its internal media test. The optical unit was therefore assessed as faulty. At this stage USB, secondary SATA and optical-disc boot paths had all failed independently, leaving physical removal of the internal storage as the remaining means of acquisition.
The laptop had not booted from its installed operating system. No evidence had been altered by a Windows startup. Three trusted external boot methods were unavailable because of unrelated firmware, bay and optical-drive conditions.
11:18 — Internal storage access
The lower enclosure was removed in the mobile workshop using ESD controls and the manufacturer’s published disassembly sequence. The battery was disconnected before the mainboard shield was lifted. The storage occupied the expected M.2 position, but it was not retained by the removable screw-and-socket arrangement shown in the service information.
The M.2-format assembly had been soldered along its connector and additional retention points. It could not be withdrawn without rework. Photographs were added to the attendance record and remote approval was obtained to desolder the device so it could be connected to an external reader.
12:07 — Mobile-workshop desoldering
The board was protected with heat shielding and the storage connections were treated with controlled hot air and soldering equipment available in the mobile workshop. The assembly was lifted without visible fracture, allowed to cool and cleaned sufficiently for inspection. The mainboard pads remained attached, although several showed excess solder and would require controlled rework before a permanent refit.
The removed storage was inserted into a known-good multiprotocol M.2 reader through the appropriate NVMe interface. The reader entered over-current protection before presenting a device identifier. After visual inspection and a second connection through an isolated bench supply, current draw oscillated without PCIe link negotiation. The same reader successfully enumerated its control device immediately afterwards.
13:02 — Escalation to main laboratory
The external-reader response could not be attributed conclusively to the storage device, solder residue, heat exposure or an interface condition. Further power attempts were stopped. The engineering manager instructed that the laptop, detached storage and acquisition materials be returned to the main laboratory for microscope inspection, controlled electrical testing and, if viable, imaging through specialist equipment.
For transport, the M.2 assembly was reseated in its original position so it would remain associated with the asset and protected by the internal shield. It was not resoldered. The disconnected battery, lower enclosure and fixings were restored, and the laptop was placed in a padded equipment bag with the chain-of-custody record.
13:26 — Mobile workshop unavailable
The service van cranked but would not start. Its fuel gauge displayed slightly above one quarter of a tank and no engine warning had been shown during the morning journey. Inspection established that the tank was empty and that the gauge sender or display was reporting an incorrect level.
To avoid delaying the laboratory assessment, a second engineer was dispatched to attend the van and arrange fuel and recovery. The onsite engineer was instructed to return by train with the sealed equipment bag. The vehicle, tools and remaining media stayed with the van pending the second attendance.
14:12 — Rail transit
The engineer boarded the next available service toward the main laboratory. The equipment bag remained in their possession. During the journey, in the vicinity of King’s Cross, the engineer elected to move between adjoining carriages using the interconnecting doors while the train was in motion.
As the second door closed, it struck the equipment bag. The closure displaced the bag, opened its incompletely secured main compartment and caused the laptop to leave the bag. The device fell into the inter-carriage area and passed through the moving gap between the carriages before the engineer could recover it. The train continued to the next safe stopping point.
14:19 — Railway incident escalation
The loss was reported immediately to onboard staff and subsequently to Transport for London control and the relevant railway operations team. The approximate location, service, carriage numbers, direction of travel and time were recorded. Track access was not permitted while passenger services remained operational.
The laptop was classified as an electronic item potentially containing a lithium-ion battery and confidential company information. Recovery was scheduled for the next engineering possession, after traction current and train movements in the affected section could be controlled. The engineer continued to the laboratory without the asset and submitted an incident statement.
Following day, 02:06 — Track recovery
Rail maintenance personnel located the laptop during the early-morning maintenance shift. It was recovered from the track area, placed in an isolation container because of the damaged battery and transferred through the railway operator’s property and safety process. The asset number remained partially legible and matched the incident record.
The company received confirmation of recovery later that morning. The device was released the following day with a formal invoice for the engineering-possession search and recovery activity. The handover also included a stern safety lecture concerning the use of interconnecting carriage doors while a train was moving.
Following day, 11:24 — Laboratory receipt
The laboratory received the laptop in the railway isolation container. Chain-of-custody entries covered the onsite engineer, rail control, maintenance recovery team and company recipient. The battery area was checked thermally before the device was moved to a fire-resistant examination bench. No attempt was made to connect power.
The laboratory photographed the device as received, collected loose material from the container and compared its condition with the images taken before rail transit. The degree and direction of new damage were materially greater than the limited mainboard rework recorded in the mobile workshop.
Laboratory report — external examination
| ENCLOSURE | Compressed to approximately 31% of original closed thickness at the principal impact line |
|---|---|
| DISPLAY | Panel, backlight and cover glass fragmented; lid folded through the keyboard deck |
| CHASSIS | Two transverse shear zones with polished compression bands and rail-side abrasion |
| PORTS | Left I/O edge absent; right-side connectors displaced into the mainboard |
| CONTAMINANTS | Ferrous residue, track ballast fragments, lubricant, brake dust and organic material |
| BATTERY | Cell group ruptured and electrically open; electrolyte residue contained within recovery packaging |
The lower case carried parallel polished bands at a spacing and profile consistent with wheel and rail compression. Fasteners had been sheared laterally rather than released through disassembly. The magnesium frame, heat pipes and hinge bar had been consolidated into a single distorted section. Several fragments recovered separately by the maintenance team matched missing areas of the display lid and base.
Laboratory report — internal examination
Low-energy radiography was completed before the enclosure was separated. It showed multiple discontinuities through the mainboard, overlapping battery material and the displaced M.2 assembly beneath the cooling structure. The laptop was then opened mechanically without applying heat to the battery area.
The mainboard had fractured across four principal planes and numerous secondary branches. Copper layers were exposed and delaminated. The processor package was split through the substrate, both memory packages were crushed, and the embedded controller and power-management components were absent from their original pads. No board-level repair could restore a stable platform for testing.
The M.2 device was no longer seated in its unresoldered position. It was recovered in three major substrate sections and several smaller fragments from beneath the mainboard shield. One fragment contained part of the controller package; the silicon die was visibly fractured. The power-management section had separated completely and conductive debris bridged multiple supply rails.
Laboratory report — storage and data assessment
Microscope and radiographic examination identified six NAND packages associated with the storage assembly. Four packages had cracked moulding and internal die damage. One had separated through its ball-grid interface with sections of the package substrate missing. The remaining package was externally complete but electrically shorted between its core and I/O supplies.
A conventional controller-level image was impossible because the storage substrate, controller and power system no longer formed an electrical device. A board transplant was not available: the original controller die was fractured, and its translation tables, wear-levelling state and hardware encryption material could not be reproduced by fitting the NAND to a donor assembly.
Chip-level recovery was also rejected. The damaged packages contained multiple dies, several of which were physically divided across the fracture lines. Even a partial raw read would lack complete pages, controller metadata and the device-specific encryption context required to reconstruct logical sectors. Applying power or removing the dies would introduce further risk without a credible path to usable data.
The physical evidence establishes that the laptop was run over by a train after leaving onsite custody. The computer, mainboard and M.2 storage assembly are destroyed beyond repair. The data is technically unrecoverable, and the original suspected malware or bootloader interference cannot now be confirmed or excluded. The asset is designated a total equipment and data loss and is to remain isolated for insured disposal.