Deutsch

Digital Forensics

AI-Driven Behavioural Forensics

Two attacks using the same malware can come from entirely different groups. Conversely, a group stays true to its habits even when it changes tools: working hours, the order of steps, preferred routes for initial access. Those habits say more than any signature.

A dark surface covered with faint scattered traces. Among them one sequence of marks repeats in a clear rhythm and is brightly highlighted.

The markers

What gets analysed

  1. 01

    Temporal patterns

    working rhythm, breaks, a recognisable time zone

  2. 02

    Order of operations

    which steps in which sequence, where shortcuts are taken

  3. 03

    Choice of tooling

    own software, or exclusively what is already on the system

  4. 04

    Target selection

    what is accessed first — that reveals the intent

  5. 05

    Error profile

    which traces are regularly overlooked

01

The benefit

From observation to anticipation

From the pattern it is possible to derive what to expect next. If a group reliably goes for the backup systems before it encrypts, then that is where detection has to be sharp. Such conclusions enter your monitoring as concrete rules — not as a general recommendation.

The analysis rests on NeoI, our own analysis engine. It compares observed behaviour against what is normal in your environment, and so also catches attackers who use nothing but legitimate tools. The results then sharpen the correlation in Strider.

02

The internal view

Inward as well

The same method catches anomalies that do not come from outside: an account systematically working through shares shortly before the person leaves, or access to data that does not fit the role. We analyse that strictly within the agreed frame and in coordination with the works council — we do not set up permanent behavioural monitoring of employees.

03

The honest view

Limits

A behavioural pattern is an indication, not proof. It helps with classification and with prioritising defence; it does not stand alone as grounds for attributing an attack to a particular group. Where evidence is what counts, the classic methods carry it — Malware Analysis and Network Forensics.

FAQ

Frequently asked questions

Can this tell us which group attacked us?

We can tell you which known way of operating the observed behaviour resembles. That is a classification, not an attribution. A behavioural pattern is not enough for a dependable statement about authorship — it can be imitated, and resemblance is not proof. We state in the report how certain a classification is.

Does this mean you monitor our employees?

No. We do not set up permanent behavioural monitoring of employees. The internal view applies for a specific reason, within a frame agreed in advance and in coordination with the works council. Where that frame is missing, we do not work.

How much data do you need for this?

Enough to tell normal behaviour from deviation — as a rule several weeks of sign-in, process and network data. For investigating a specific incident the logs from that period are often enough. What is missing we say at the outset, rather than noting it later as uncertainty.

Does this replace classic forensics?

No, it complements it. Behavioural analysis shows what to watch for and what would come next. The proof of what actually happened is carried by malware analysis and network forensics. Together they make the picture.

What happens to the findings after the investigation?

They become concrete detection rules in your monitoring — that is the actual return. A report describing how the attacker operated without anything changing in your detection was not worth the work.

Digital Forensics

More in this area

Malware Analysis

We take malware apart in an isolated environment and deliver concrete detection rules for your systems rather than a la…

View

Network Forensics

Network traffic reveals what has long been deleted on endpoints. We reconstruct entry, lateral movement and exfiltratio…

View

Cloud Forensics

There is no disk to image in the cloud. We secure logs, configuration states and identity data before the provider rete…

View

Mobile Forensics

Company phones often hold more business secrets than any computer. We secure and examine them to an evidentiary standar…

View

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.