Skip to content
Talk to a Security Expert
DEFENSIVE SECURITY / INVESTIGATION & EVIDENCE

Digital Forensics

Understand the evidence behind a security incident and reconstruct what happened.

After an incident, the pressing questions are specific: how did they get in, how long were they there, what did they reach, and is it actually over. Answering them means working from evidence rather than inference.

Forensic work reconstructs a sequence from artifacts systems leave behind — authentication records, process activity, file changes, network connections. Individually these are fragments; assembled in order they become a timeline that either supports a conclusion or rules it out.

Evidence to findings

Artifacts become a timeline; a timeline becomes an answer.

  1. EVIDENCEDigital evidenceSources preserved from the systems in scope
  2. ARTIFACTSArtifactsThe specific records those sources contain
  3. TIMELINETimelineArtifacts placed in sequence across systems
  4. ANALYSISAnalysisWhat the sequence indicates, and what it excludes
  5. FINDINGSFindingsA documented account of what the evidence supports

Conceptual process. What can be recovered depends on what was preserved, what was logged and how long it was retained.

// CONTEXT

Evidence has a short shelf life

Much of what matters is volatile or short-lived. Memory contents disappear on reboot, logs roll over, temporary files are cleaned up, and a well-intentioned rebuild removes the record of everything that came before it.

This is why the response to a suspected incident should be to preserve first. Restoring service is the goal, but doing it before evidence is captured usually means the question of what actually happened can no longer be answered.

// EVIDENCE TIMELINE

Artifacts placed in sequence.

Illustrative entries showing how a reconstructed timeline reads. These are examples, not real incident evidence.

RECONSTRUCTED TIMELINE — ILLUSTRATIVE0/7
00:42Authentication event recorded from an unrecognised location
01:17Process activity observed outside the host's normal pattern
01:58Scheduled task created on the affected endpoint
02:03File written to a directory not used by the application
02:46Outbound network connection to an unfamiliar destination
03:12Investigation marker — evidence preserved for analysis
03:40Timeline correlated across endpoint and identity sources
ILLUSTRATIVE EXAMPLE — NOT REAL INCIDENT EVIDENCE
// CAPABILITIES

Focus areas

Findings are constrained by available evidence. Where the data does not support a conclusion, the report says so.

// WHEN THIS APPLIES

When Do You Need to Know What Actually Happened?

01SITUATIONEstablishing scope after an incidentDetermining what was actually reached, not what could have been.
02SITUATIONSuspected insider activityUnderstanding account or data activity with care over process.
03SITUATIONConfirming eradicationVerifying that access is genuinely closed.
04SITUATIONSupporting a wider processProducing a clear technical account for others to rely on.
// WHAT YOU RECEIVE

Output your team can act on.

Which of these apply depends on engagement scope.

SECURITY VISIBILITY

A clearer view of what activity is happening across the environment in scope.

MONITORING INSIGHTS

What the monitored signals show over time, and what changed.

DETECTION FINDINGS

Activity identified as worth attention, with the reasoning behind it.

INVESTIGATION CONTEXT

What was examined, what it indicated and what was ruled out.

INCIDENT REPORTING

A written account of an incident: timeline, impact and actions taken.

RESPONSE GUIDANCE

Recommended actions, and where a decision needs to sit with your team.

SECURITY IMPROVEMENT RECOMMENDATIONS

Where detection, logging or process could be strengthened.

// FREQUENTLY ASKED

Questions we get asked before an engagement.

Discuss a Forensic Investigation

Tell us what happened, what has been preserved and what you need to establish. What is still available shapes what an investigation can answer.