08
Service 08Endpoint · Cloud · Email · Evidence preservation

Digital Forensics

We establish what happened, how the attacker entered, which systems were affected, and which evidence supports the conclusion.
At a glance
EngagementIncident · Suspected compromise · Legal request
SourcesEndpoint · Cloud · Email · Logs
Led bySenior DFIR specialist
OutputTimeline, evidence, and forensic report
§ 01Overview
Digital Forensics
We investigate endpoints, servers, identities, cloud environments, and business email. Evidence is preserved, timelines are reconstructed, and findings are written for technical, management, and legal stakeholders.
§ 02What's included

What the service covers.

Engage any item on its own, or combine them into a single engagement.
01
Endpoints and servers
Disk, memory, process, account-activity, and malware-trace analysis.
02
Cloud and identity
Authentication, administrative activity, token, privilege, and audit-log analysis.
03
Business email
Investigation of account takeover, malicious rules, forwarding, BEC, and data theft.
04
Network and security logs
Correlation of firewall, VPN, EDR, SIEM, and application logs.
05
Evidence preservation
Forensic copies, hashes, and a documented chain of custody.
06
Compromise scoping
Identification of affected systems, accounts, data, and the compromise window.
§ 03How we approach it

A clear methodology, every time.

1
Preserve
Secure relevant sources without unnecessary alteration and document every handling step.
2
Collect
Create forensic copies and collect endpoint, cloud, network, and email evidence.
3
Analyse
Correlate artefacts, identify the entry point, and reconstruct the incident timeline.
4
Report
Deliver findings, evidence, limitations, and recommendations for recovery and hardening.
§ 04What you get

Results you can act on.

Every engagement ends with documented findings and evidence, written for the technical team and for the board.
01Forensic incident timeline
02Affected systems, accounts, and data
03Documented indicators of compromise
04Preserved evidence and chain-of-custody record
05Report for technical, management, and legal stakeholders

Independent and vendor-neutral. We don't resell the tools we test.

Our only product is expertise and evidence, so our advice has no agenda but yours.
Independent
Vendor-neutral. No licences to sell, no conflicts of interest.
Senior-led
Every engagement is run by senior engineers, not handed to a queue.
Evidence-led
Reproducible findings and documented proof, not severity labels.
Regulator-ready
Built to satisfy NIS2, DORA, ISO 27001, and GDPR by design.
FAQ

Questions, answered

When should digital forensics be engaged?
As soon as compromise, data theft, account takeover, or insider misuse is suspected. Early engagement preserves volatile evidence and reduces the risk of false conclusions.
Which systems can you analyse?
Endpoints, servers, cloud and identity platforms, business email, EDR/SIEM telemetry, and network and application logs, subject to data availability.
Can the investigation be performed remotely?
Yes. Much of the collection and analysis can be performed remotely. Where physical acquisition or special evidence handling is required, we arrange on-site work.
Is the report suitable for court?
We provide a technical report and documented chain of custody. Where formal expert-witness evidence is required, we work alongside counsel and an authorised forensic expert.

Ready to scope digital forensics?

Our team will help you define the scope on a 30-minute call.
Book a scoping call or email contact@raptoric.com