Digital Forensics & Incident Response
Answer the question you will be asked later, not the one you are panicking about now.
During an incident, everyone wants to know whether it is over. The questions that matter afterwards are different and harder: what did they touch, when did they get in, what left the building, and can you prove it. Those answers depend almost entirely on decisions made before anything happened, on what was logged, for how long, and whether the first responder preserved the machine or rebooted it. We do both halves of that: the response itself, and the forensic readiness work that makes the next response answerable.
- Preserve first, so the answer still exists later
- Hour onePreserve first, so the answer still exists later
- Chain of custody on every acquisition
- AttestedChain of custody on every acquisition
- What was reached, stated with the evidence
- ScopedWhat was reached, stated with the evidence
Sounds like
You might recognise one of these.
Something is wrong and we do not know how far it goes.
We need to tell a regulator what was accessed and we cannot.
Our logs roll over after seven days.
An employee left and we think they took something with them.
The incident is closed but nobody wrote down what actually happened.
What this includes
The work, specifically.
Not every engagement needs all of it. This is the range we cover and what each part is actually for.
Incident response
Scoping, containment and eradication with an eye on evidence throughout. The instinct to reimage the machine and move on is the single most expensive reflex in this work, and we get in front of it in the first hour.
Host and memory forensics
Sound acquisition of disk and volatile memory, timeline reconstruction from filesystem, registry, event log and browser artifacts, deleted-data recovery, and analysis of what executed and what persisted. Chain of custody documented from acquisition onward, because an answer nobody can attest to is not usable.
Log and network analysis at scale
Correlating authentication, endpoint, proxy, DNS and cloud audit logs across the window that matters, in Elastic or the SIEM you already run. This is where the intrusion timeline actually comes from, and it is the work that most engagements underestimate.
Malware analysis and reverse engineering
Detonation in an instrumented sandbox with network simulation, then static reversing of the sample to establish capability, persistence, configuration and indicators. What a sample can do matters more to your scoping decisions than what a vendor’s classification label says it is.
Insider, misuse and internal investigation
Data-exfiltration analysis across removable media, cloud sync, email and print, conducted with the restraint these cases require: proportionate scope, documented authorization, and findings written so that they survive a lawyer reading them.
Forensic readiness engineering
The proactive half. Log coverage and retention aligned to the questions you would need to answer, tamper-evident audit trails, endpoint telemetry that captures process lineage, and a tested response plan. Most of what makes an investigation possible is a build decision made months earlier.
What you get
Deliverables, not documents.
- Incident timeline with the evidence behind each entry
- Scope determination: systems, accounts and data actually affected
- Indicators of compromise and detection content for your own tooling
- Malware capability analysis where a sample is recovered
- Documented chain of custody for every acquired image
- Written report suitable for regulators, insurers or counsel
- Root-cause findings and a prioritized hardening backlog
- Blameless postmortem run with the team, producing fixes rather than blame
Shapes
How this usually runs.
Incident response
Days to weeksEngaged during or immediately after an event. Containment, investigation, scoping and the report. Retainer clients get a defined response window; without one we take the call and tell you honestly how fast we can be there.
Forensic investigation
2–6 weeksA defined question (what was taken, who did it, when did it start) answered with acquired evidence and a report written to be read by someone outside engineering.
Forensic readiness review
2–4 weeksWe take three plausible incident scenarios and test whether your current logging and tooling could answer them. Usually it cannot, and the gap list is the deliverable.
Tooling
What we build it with.
No tool here was picked because it was new. Where we do reach for something novel, it is in one place, for a stated reason, and it is written down.
- Acquisition
- Analysis
- Malware
- Frameworks
Proof
Where this has been done.
Questions
Forensics & IR, honestly.
Isolate rather than power off, because memory is where a lot of the answer lives and it does not survive a shutdown. Do not reimage anything. Stop log rotation on anything relevant. Write down what you have already done and when, including the things you would rather not have done, because an undocumented action taken by a responder is indistinguishable from an attacker’s action later.
Usually yes, and usually earlier than people want to. Beyond the regulatory notification clocks, engaging under counsel affects the privilege position of the investigation and its work product. We work either way and we will follow your counsel’s instructions on scope and reporting, but we will raise the question in the first conversation.
Yes, and check your policy before you need to: many cyber policies require the use of a panel firm or prior written approval, and engaging outside that can affect coverage. We have no objection to working alongside a panel firm on the parts they are not covering.
Then we say so rather than filling the gap with inference. An honest report that says a period cannot be reconstructed is worth more than a confident narrative built on nothing, particularly if it is going to a regulator. It is also the single most common finding, which is why forensic readiness is a service and not an afterthought.
Further reading
What we think about this, at length.
Next step
Tell us what’s breaking.
Forty-five minutes, no charge, no deck. We’ll tell you what we’d do, what it would likely cost, and whether you should be building this at all.