What we examine
- Computers, servers and cloud accounts involved in an intrusion, ransomware event or data breach
- System, network, authentication and application logs, and the gaps in them
- Malware, remote-access tools and persistence mechanisms, and what they were capable of
- Insider activity: access to data the user was or wasn't authorized to reach, copying, exfiltration and deletion
- The response itself: what was preserved, what was changed, and whether the incident response was handled in a forensically sound way
Questions we help answer
- How did the attacker get in, what did they do, and over what period?
- What data was accessed or exfiltrated, and what can and cannot be determined from the surviving records?
- Who is responsible? What does the evidence support about attribution, and how strongly?
- Did the activity exceed authorized access, a key question in Computer Fraud and Abuse Act matters?
- Were the security controls and the response reasonable, given what was known and available at the time?
How it fits your case
We advise early on preservation, before logs roll over and systems are rebuilt. We then reconstruct the incident timeline and report findings, and their limits, in a form suited to litigation, regulators or insurers. The methods follow published incident-response and forensics guidance, including NIST guidance for integrating forensic techniques into incident response.