Malware Analysis
We take malware apart in an isolated environment and deliver concrete detection rules for your systems rather than a la…
ViewDigital Forensics
Classic forensics starts with an image of the hard disk. In the cloud that disk does not exist — and the logs that take its place disappear after a retention period set by the provider. Cloud forensics is therefore above all a race against time.

The time pressure
Retention periods for logs differ by provider, plan and log type, and some are short. Some of the most informative data is only available in higher licence tiers and cannot be generated retroactively. Anyone who waits three weeks after a suspicion may already have lost the decisive source. So our first step is always preservation, not analysis.
The scope
sign-ins, failed attempts, factor resets, newly granted permissions
forwarding rules, delegations, third-party access, deleted items
bulk downloads, external sharing, version histories
newly created resources, changed network rules, retrieved secrets
deviations from the documented target state
The sequence
In the majority of cases it does not start with malware but with a taken-over account — through phishing, reused passwords or bypassing the second factor. What follows is almost always the same: an inconspicuous forwarding rule in the mailbox, the creation of a second way in as a fallback, then the actual access. How well your workforce holds up against the first step is what a Social Engineering Assessment tests.
The boundary
The provider secures the platform, you secure your configuration and your identities. Most of the incidents we investigate arise on the second side of that boundary. Where there is no target state to check against, we establish one with Sightadel — the control catalogues of NIS2, DORA, ISO 27001 and the GDPR are already held there.
The follow-through
Every investigation produces a list of changes that prevent a repeat. Ongoing monitoring then runs through SOC as a Service; detecting new anomalies is handled by AI threat detection.
FAQ
Two things, immediately: raise logging to the highest level available, and start exporting the logs you already have. Both cost nothing and cannot be done retroactively. Delete nothing, change no rules, and do not hastily disable the suspicious account — a disabled account warns the attacker before you know what they did.
Yes, but on a narrower basis. Some of the most informative logs are tied to higher tiers and cannot be generated retroactively. We tell you at the outset which questions your licence scope can answer and which stay open — rather than selling you a gap as a result at the end.
For the platform, yes. For your configuration, your permissions and your identities, no. Practically every incident we investigate arises on your side of that boundary — usually through a taken-over account. The provider supplies the logs; the assessment is yours to make.
Whatever is reachable through the usual interfaces we collect ourselves. Requests to the provider beyond that take time and do not always succeed. So we plan the investigation to work with the data you can reach yourself.
There is no storage medium to image and no memory to capture. In their place are logs that belong to somebody else and disappear on somebody else's schedule. So the order reverses: preserve first, then ask what should be investigated.
Digital Forensics
We take malware apart in an isolated environment and deliver concrete detection rules for your systems rather than a la…
ViewNetwork traffic reveals what has long been deleted on endpoints. We reconstruct entry, lateral movement and exfiltratio…
ViewCompany phones often hold more business secrets than any computer. We secure and examine them to an evidentiary standar…
ViewTools change, habits persist. We analyse how an attacker operates and derive where they will start next time.
ViewContact
Talk to us before somebody else does. The first conversation is free and we reply the same business day.