Blackbourne Worldwide BlackbourneWorldwide

Home / Cyber Forensics

Incident response

Who, what, when, why and how.

With every attack we initiate a full-scale cyber-forensic investigation. Knowing that an incident happened is not the same as understanding it — and without the second, the same intrusion returns.

Emergency Response Team — isolates and mitigates threats in under 30 minutes. Available 24/7/365. If you are in an active incident, say so and you go to the front of the queue. Contact the ERT

The five questions

Every attack is investigated the same way.

Who

Which account, which host, which operator or group — established from artefacts and behaviour rather than assumption.

What

What was accessed, changed, copied or installed. The scope of impact, and what was not touched.

When

A reconstructed timeline: first access, dwell time, each action in sequence, and when containment took effect.

Why

Objective and motivation, inferred from what was targeted and what was ignored.

How

The path in, the persistence used, the tools and infrastructure, and the techniques that let it stay quiet.

Then what

Infrastructure hardening and advanced threat detection derived from the answers — not a generic checklist.

Reverse engineering

All malware goes to our internal R&D department.

Any sample recovered — during incident response or during a testing engagement — is reverse engineered and analysed by our research team. Static and dynamic analysis in isolation establishes capability, persistence, evasion and infrastructure.

The holistic understanding of the threat and the malware is what allows for infrastructure hardening and advanced threat detection. Without it, you are blocking a file name; with it, you are detecting a behaviour.

Security research & malware analysis

ArtefactWhat we determine
Binaries & scriptsCapability, packing, persistence mechanism, indicators of compromise.
Memory imagesRunning processes, injected code, credentials, network connections at capture.
Disk imagesDeleted artefacts, timeline, user activity, staged data.
Network capturesCommand-and-control patterns, exfiltration, lateral movement.
Log sourcesReconstructed sequence across identity, endpoint, network and cloud.

Response

How an incident runs.

Contain

Isolate affected hosts and accounts, stop the spread, and preserve evidence while doing it.

Preserve

Forensically sound capture of memory, disk and logs before remediation destroys the record.

Investigate

Establish the five questions and the full scope of access the adversary held.

Eradicate and harden

Remove persistence, close the path used, and add the detections the investigation showed were missing.

Retainer

Incident response is better arranged before you need it.

Agreed terms

Rates, escalation contacts and data handling settled in advance, so an incident does not begin with procurement.

Pre-agreed authority

Containment decisions are made in the first minutes, not after a call chain.

Readiness review

A review of your logging and evidence preservation, because an investigation is only as good as the record that survives.

Arrange a retainer

In an incident, or preparing for one?

If it is happening now, tell us — you will be routed to the Emergency Response Team immediately. If it is preparation, we will review your readiness and tell you what would fail first.