This report details a digital forensic investigation using the ProDiscover tool. The scenario involves an employee suspected of data theft, prompting a forensic analysis of their computer. The report covers the use of ProDiscover to discover hidden files within an image file, including a Word document, an Excel file, and a picture. The file system data acquisition method is explained, highlighting its role in recovering deleted files. The report discusses the importance of drive imaging and hash values for evidence integrity and admissibility in court. Physical and file system data acquisition techniques are recommended for the investigation. The methodology includes creating an image file using ProDiscover and recovering deleted files. Finally, the report explores data recovery techniques, emphasizing the importance of file carving and the challenges of data restoration from deleted or damaged drives. The report also includes a bibliography of relevant sources.