Digital forensics and cybercrime investigation
What you do in the first hours of a suspected compromise determines whether you will ever be able to prove what happened. Rebuilding the machine destroys the evidence. So does logging in to "have a look".
Forensic work establishes what an attacker did, when they entered, what they reached, and whether data left — to a standard that holds up in a regulatory submission or a courtroom.
What the engagement includes
- Forensic acquisition of disk, memory and cloud artefacts with verified hashes
- Chain of custody maintained and documented throughout
- Timeline reconstruction across endpoint, network and identity sources
- Malware analysis and reverse engineering of recovered samples
- Data exfiltration assessment: what left, when, and how much
- FIR-ready documentation for cybercrime reporting in India
- Expert documentation for legal and regulatory proceedings
- Post-incident review and remediation so the same route closes
Who this is for
Organisations with a confirmed or suspected breach, insider incidents, fraud investigations, and any situation likely to end in a regulator conversation or litigation.
How it runs
Every engagement follows the same five stages — discover, architect, implement, validate, defend. See how we work →
How the engagement runs
Five stages, with indicative timing. Exact dates are confirmed at scoping.
-
01
Preserve
Stop the loss of evidence first: isolate without powering down, protect logs close to rotation.
Hour 0 -
02
Acquire
Forensic images of disk, memory and cloud artefacts with verified hashes and documented chain of custody.
Day 1 -
03
Analyse
Timeline reconstruction across endpoint, network and identity. Malware reversed where samples are recovered.
Days 2–7 -
04
Determine impact
What was accessed, what left, whose data was involved, and what must be notified to whom.
Days 5–10 -
05
Report & support
Findings documented to evidentiary standard, with FIR-ready material and expert support if it proceeds.
Days 10+