Overview
After a security incident, leadership, insurers, regulators and sometimes courts need clear answers: How did attackers get in? What did they access? Is the threat gone? Digital forensics provides those answers through careful, evidence-based investigation.
Our analysts collect and preserve evidence from endpoints, servers, memory, cloud platforms, email systems and logs using forensically sound methods and documented chain of custody. We reconstruct attacker timelines, determine root cause and data impact, and analyse malware samples to understand capabilities, persistence and indicators of compromise.
Forensic investigations are available as part of active incident response or as standalone investigations, such as insider threat or suspected data theft.
What's included
Our approach
- ScopeDefine questions, systems and legal considerations.
- PreserveCollect evidence forensically with chain of custody.
- AnalyseTimeline reconstruction and malware analysis.
- ConcludeRoot cause, scope and data impact.
- ReportClear reports for each audience.
What you receive
- Chain-of-custody documentation
- Attack timeline
- Malware analysis report and IOCs
- Data impact assessment
- Executive and technical reports
Standards & frameworks
- NIST SP 800-86
- ISO/IEC 27037
- ISO/IEC 27035
- MITRE ATT&CK
Frequently asked questions
Should we turn off infected computers?
Avoid powering off systems before speaking with responders — volatile memory can contain critical evidence. Isolate them from the network instead.
Can your reports be used in legal proceedings?
We follow forensically sound practices and document chain of custody; work with your legal counsel on specific requirements.
Do you analyse malware samples we send you?
Yes. Submit samples through a secure channel agreed with our team.