Malware Analysis
We take malware apart in an isolated environment and deliver concrete detection rules for your systems rather than a la…
ViewDigital Forensics
Two attacks using the same malware can come from entirely different groups. Conversely, a group stays true to its habits even when it changes tools: working hours, the order of steps, preferred routes for initial access. Those habits say more than any signature.

The markers
working rhythm, breaks, a recognisable time zone
which steps in which sequence, where shortcuts are taken
own software, or exclusively what is already on the system
what is accessed first — that reveals the intent
which traces are regularly overlooked
The benefit
From the pattern it is possible to derive what to expect next. If a group reliably goes for the backup systems before it encrypts, then that is where detection has to be sharp. Such conclusions enter your monitoring as concrete rules — not as a general recommendation.
The analysis rests on NeoI, our own analysis engine. It compares observed behaviour against what is normal in your environment, and so also catches attackers who use nothing but legitimate tools. The results then sharpen the correlation in Strider.
The internal view
The same method catches anomalies that do not come from outside: an account systematically working through shares shortly before the person leaves, or access to data that does not fit the role. We analyse that strictly within the agreed frame and in coordination with the works council — we do not set up permanent behavioural monitoring of employees.
The honest view
A behavioural pattern is an indication, not proof. It helps with classification and with prioritising defence; it does not stand alone as grounds for attributing an attack to a particular group. Where evidence is what counts, the classic methods carry it — Malware Analysis and Network Forensics.
FAQ
We can tell you which known way of operating the observed behaviour resembles. That is a classification, not an attribution. A behavioural pattern is not enough for a dependable statement about authorship — it can be imitated, and resemblance is not proof. We state in the report how certain a classification is.
No. We do not set up permanent behavioural monitoring of employees. The internal view applies for a specific reason, within a frame agreed in advance and in coordination with the works council. Where that frame is missing, we do not work.
Enough to tell normal behaviour from deviation — as a rule several weeks of sign-in, process and network data. For investigating a specific incident the logs from that period are often enough. What is missing we say at the outset, rather than noting it later as uncertainty.
No, it complements it. Behavioural analysis shows what to watch for and what would come next. The proof of what actually happened is carried by malware analysis and network forensics. Together they make the picture.
They become concrete detection rules in your monitoring — that is the actual return. A report describing how the attacker operated without anything changing in your detection was not worth the work.
Digital Forensics
We take malware apart in an isolated environment and deliver concrete detection rules for your systems rather than a la…
ViewNetwork traffic reveals what has long been deleted on endpoints. We reconstruct entry, lateral movement and exfiltratio…
ViewThere is no disk to image in the cloud. We secure logs, configuration states and identity data before the provider rete…
ViewCompany phones often hold more business secrets than any computer. We secure and examine them to an evidentiary standar…
ViewContact
Talk to us before somebody else does. The first conversation is free and we reply the same business day.