Cybersecurity
Digital forensics
What happened, how they got in and what they took.
What this work consists of
We preserve the evidence, reconstruct the timeline, and state what actually happened, whether on a seized device or in system records. If the outcome may end up in court, the chain of custody must be intact from the very first touch. That is why the worst decision when facing a suspicion is letting the IT team dig in before calling someone.
What we examine depends on the case. For files and records, we analyze access, application, network, and email logs together with the files involved, to establish misuse, information theft, or intrusion. For devices and computers, the copy is made bit by bit, the original is preserved intact, and custody is documented, so the analysis cannot be challenged later.
The depth matches what is at stake. Analyzing what is visible resolves most internal inquiries. Going further, into system artifacts, execution traces, and correlation across sources, supports a disciplinary decision or a conversation with the regulator. The advanced level recovers what was deleted, detects attempts to hide tracks, and produces the expert forensic report.
We need access to the material to examine and formal authorization from its owner. You receive the hour-by-hour timeline and the technical report; for device examinations, the documented chain of custody; and, at the advanced level, the signed expert forensic report, in a format accepted in court.
How we conduct it, stage by stage
The stages and deliverables below describe the Files and system logs · Intermediate modality. The other modalities appear when you request the proposal.
Evidence preservation
We copy and seal before any analysis. The original stays intact and custody is documented from the first touch.
Analysis
We rebuild what happened from the traces, cross-checking different sources until the timeline holds together.
Report
We consolidate the findings into a report where every item comes with severity, evidence and the path to fix it. We write to be read by the people who will act, not to fatten pages.
What is not included
- Containing an incident in progress, which is incident response and comes first
- Recovering affected data or systems, which is restoration work, not forensics
- Recovering deleted content and detecting anti-forensics outside the advanced level, which is the level that produces that result
- Representation in court: we deliver the report, the legal argument belongs to your lawyers
- Repairing or returning the device in working condition: we work on the copy and preserve the original as evidence
- Attributing actions to a person when the traces do not support it: we state what the evidence proves, not beyond it
- Breaking confidentiality or accessing equipment without formal authorization from the owner
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.