Who
Which account, which host, which operator or group — established from artefacts and behaviour rather than assumption.
Home / Cyber Forensics
Incident response
With every attack we initiate a full-scale cyber-forensic investigation. Knowing that an incident happened is not the same as understanding it — and without the second, the same intrusion returns.
The five questions
Which account, which host, which operator or group — established from artefacts and behaviour rather than assumption.
What was accessed, changed, copied or installed. The scope of impact, and what was not touched.
A reconstructed timeline: first access, dwell time, each action in sequence, and when containment took effect.
Objective and motivation, inferred from what was targeted and what was ignored.
The path in, the persistence used, the tools and infrastructure, and the techniques that let it stay quiet.
Infrastructure hardening and advanced threat detection derived from the answers — not a generic checklist.
Reverse engineering
Any sample recovered — during incident response or during a testing engagement — is reverse engineered and analysed by our research team. Static and dynamic analysis in isolation establishes capability, persistence, evasion and infrastructure.
The holistic understanding of the threat and the malware is what allows for infrastructure hardening and advanced threat detection. Without it, you are blocking a file name; with it, you are detecting a behaviour.
| Artefact | What we determine |
|---|---|
| Binaries & scripts | Capability, packing, persistence mechanism, indicators of compromise. |
| Memory images | Running processes, injected code, credentials, network connections at capture. |
| Disk images | Deleted artefacts, timeline, user activity, staged data. |
| Network captures | Command-and-control patterns, exfiltration, lateral movement. |
| Log sources | Reconstructed sequence across identity, endpoint, network and cloud. |
Response
Isolate affected hosts and accounts, stop the spread, and preserve evidence while doing it.
Forensically sound capture of memory, disk and logs before remediation destroys the record.
Establish the five questions and the full scope of access the adversary held.
Remove persistence, close the path used, and add the detections the investigation showed were missing.
Retainer
Rates, escalation contacts and data handling settled in advance, so an incident does not begin with procurement.
Containment decisions are made in the first minutes, not after a call chain.
A review of your logging and evidence preservation, because an investigation is only as good as the record that survives.
If it is happening now, tell us — you will be routed to the Emergency Response Team immediately. If it is preparation, we will review your readiness and tell you what would fail first.