This report details a computer forensic investigation involving a scenario where an employee deleted files from their hard drive before leaving the company. The investigation focuses on recovering these deleted files using the ProDiscover tool. The report covers digital clues, acquisition methods (specifically live acquisition), and essential methods like drive imaging and chain of custody. Section 2 outlines the steps taken to acquire an image of a USB drive using ProDiscover Basic and recover the deleted files (encrypted .doc, .xlsx, and .jpg files). The report also mentions the use of Autopsy for investigating a 2GB drive. The conclusion emphasizes the growing importance of digital forensics in addressing online malicious activities and cybercrime, highlighting the role of computer forensics in preserving online operations and ensuring public safety. The report also includes a bibliography of relevant sources.