Skip to main content
IMMEDIATE START, SCOPE DEPENDENT

Digital Forensics & Incident Response

Establish what happened, how far it went, and what to do next

The first hours of an incident decide how much you will be able to establish later. The single most common and most costly mistake is wiping or rebuilding affected machines before evidence is captured, which permanently destroys the artefacts needed to determine scope. Investigations preserve evidence first, then reconstruct the timeline from memory, disk, and network sources to establish entry point, dwell time, lateral movement, and what was actually accessed.

When you need this

  • You have found a ransom note, or files have been encrypted
  • There are logins, transfers, or processes nobody can account for
  • An alert fired and you cannot tell whether it was a real compromise
  • You need a defensible account of an incident for insurers, regulators, or a court

What is included

Incident triage

Rapid assessment of what is affected, whether the attacker still has access, and what must be contained immediately.

Evidence acquisition

Forensically sound memory and disk imaging with hash verification and documented chain of custody.

Memory forensics

Volatility-based analysis to recover running processes, injected code, network connections, and credentials in memory.

Timeline reconstruction

Correlation of filesystem, registry, event log, and network artefacts into a single defensible sequence of events.

Malware artefact analysis

Identification and analysis of any malicious binaries recovered, with extracted indicators of compromise.

How the engagement runs

01

Contain

Isolate affected systems from the network without powering them off, which would destroy volatile memory.

02

Preserve

Capture memory and disk images with hash verification before any remediation touches the systems.

03

Analyse

Reconstruct the timeline and determine entry point, dwell time, lateral movement, and data accessed.

04

Report

Deliver findings, indicators of compromise, and a hardening plan to prevent recurrence.

What you receive

  • Forensic investigation report suitable for legal and insurance use
  • Documented incident timeline with supporting evidence
  • Indicators of compromise for detection and threat hunting
  • Chain of custody documentation
  • Containment and recovery recommendations
  • Root cause analysis and hardening guidance

Tooling

VolatilityAutopsyFTK ImagerThe Sleuth KitWiresharkYARAMagnet AXIOM

Common questions

What should we do first if we think we have been breached?

Preserve evidence before cleaning anything up. Do not wipe or rebuild affected machines, because that destroys the forensic artefacts needed to establish what happened and how far the attacker reached. Isolate affected systems from the network rather than powering them off, since shutting down loses volatile memory. Then rotate credentials from a known-clean device and get forensic acquisition started.

Can you help if we have already rebuilt the affected machines?

Often, yes, though the picture will be less complete. Useful evidence usually survives elsewhere: firewall and proxy logs, email gateway records, EDR telemetry, cloud audit logs, backups, and other endpoints the attacker touched. An investigation can still establish scope from those sources, but acting before rebuilding always produces a stronger result.

Will the report hold up for insurance or legal purposes?

Reports are written to be defensible, with documented chain of custody, hash-verified images, and findings traced back to specific evidence rather than assertion. Note that this is investigative work, not legal advice, and your legal counsel should be involved early where litigation or regulatory notification is likely.

Discuss a digital forensics & incident response engagement

Scoping conversations are free and produce a fixed quote before any work begins.

Get in touch

Other services