Forensic Investigations
Standalone digital forensics: acquire the evidence, reconstruct the timeline, and establish what was actually accessed.
When an incident is already over — or was discovered late — the question is no longer how to contain it but what happened, how far it reached, and what has to be disclosed. We work from images rather than live systems, preserve chain of custody throughout, and separate what the evidence proves from what it merely suggests.
What the engagement covers
- Forensic acquisition of hosts, disks, memory and cloud audit trails
- Write-blocked imaging with documented chain of custody
- Timeline reconstruction across endpoint, network and identity logs
- Malware and persistence-mechanism analysis
- Data-access and exfiltration scoping to support disclosure decisions
What you receive
- Investigation report separating established fact from assessment
- Annotated incident timeline with supporting artefacts
- Indicators of compromise in a form your tooling can ingest
- Evidence register and preserved images retained for the agreed period
- Findings walkthrough for legal, insurance or executive stakeholders
Typical duration: 1 to 3 weeks depending on the number of systems in scope
Pricing: the listed figure is a starting point; final price follows a scoping call and depends on the size of the environment.
Authorisation: testing begins only once a scope and authorisation letter is signed by an accountable owner of the systems in scope.
-
ReferenceBBS-IR-FORENSIC
Every engagement runs under a signed scope and authorisation letter.
Mutual NDA before scoping. Your findings are never shared or resold.
We re-verify every finding within 30 days of remediation at no cost.
Comments (0)
Your review appreciation cannot be sent
Report comment
Report sent
Your report cannot be sent