§ 01Overview
Digital Forensics
We investigate endpoints, servers, identities, cloud environments, and business email. Evidence is preserved, timelines are reconstructed, and findings are written for technical, management, and legal stakeholders.
§ 02What's included
What the service covers.
Engage any item on its own, or combine them into a single engagement.
01
Endpoints and servers
Disk, memory, process, account-activity, and malware-trace analysis.
02
Cloud and identity
Authentication, administrative activity, token, privilege, and audit-log analysis.
03
Business email
Investigation of account takeover, malicious rules, forwarding, BEC, and data theft.
04
Network and security logs
Correlation of firewall, VPN, EDR, SIEM, and application logs.
05
Evidence preservation
Forensic copies, hashes, and a documented chain of custody.
06
Compromise scoping
Identification of affected systems, accounts, data, and the compromise window.
§ 03How we approach it
A clear methodology, every time.
1
Preserve
Secure relevant sources without unnecessary alteration and document every handling step.
2
Collect
Create forensic copies and collect endpoint, cloud, network, and email evidence.
3
Analyse
Correlate artefacts, identify the entry point, and reconstruct the incident timeline.
4
Report
Deliver findings, evidence, limitations, and recommendations for recovery and hardening.
Independent and vendor-neutral. We don't resell the tools we test.
Our only product is expertise and evidence, so our advice has no agenda but yours.
Independent
Vendor-neutral. No licences to sell, no conflicts of interest.
Senior-led
Every engagement is run by senior engineers, not handed to a queue.
Evidence-led
Reproducible findings and documented proof, not severity labels.
Regulator-ready
Built to satisfy NIS2, DORA, ISO 27001, and GDPR by design.
FAQ
Questions, answered
When should digital forensics be engaged?
As soon as compromise, data theft, account takeover, or insider misuse is suspected. Early engagement preserves volatile evidence and reduces the risk of false conclusions.
Which systems can you analyse?
Endpoints, servers, cloud and identity platforms, business email, EDR/SIEM telemetry, and network and application logs, subject to data availability.
Can the investigation be performed remotely?
Yes. Much of the collection and analysis can be performed remotely. Where physical acquisition or special evidence handling is required, we arrange on-site work.
Is the report suitable for court?
We provide a technical report and documented chain of custody. Where formal expert-witness evidence is required, we work alongside counsel and an authorised forensic expert.