Network Forensics
Network traffic reveals what has long been deleted on endpoints. We reconstruct entry, lateral movement and exfiltratio…
ViewDigital Forensics
A suspicious file on its own says very little. It becomes interesting through three questions: what does it do? Where did it come from? And what would have let us catch it earlier?

The method
Effort rises sharply across the levels. So after the first pass we decide together with you how deep to go — for widespread commodity malware the analysis often ends at level one.
file structure, strings, embedded resources and signatures — without execution
controlled execution in an isolated environment, observing file system, registry, processes and network
taking the code apart where obfuscation or packers block the first two levels
The result
what the sample actually does on an infected system
file names, hashes, registry keys, network destinations
Detection rules in a format your systems can take over directly
known family, similarities to earlier incidents, probable objective
Recommendations for clean-up and for checking whether other systems are affected
The follow-through
The urgency
If the attack is still under way, analysis is not the first step. What counts then is containment — get in touch through Instant Response, and the analysis runs alongside. For a dependable reconstruction of the whole incident we fall back on Digital Forensics.
FAQ
The first level produces a result within hours, often the same day. A dynamic analysis usually takes one to two days. Reverse engineering cannot honestly be predicted — with heavily obfuscated code it can turn into weeks. After the first pass we tell you what the next step would cost, before you commission it.
You hand the sample over through a secured route we agree in advance — not as an email attachment. If you are unsure whether a file is executable at all, do not touch it and call us first. Mishandling regularly destroys exactly the traces we need.
There is usually still something left: the scanner quarantine, copies in temporary directories, traces in memory if the system is still running. Do not shut the machine down before we have spoken — memory is the most volatile source and the first one lost.
Yes, and that is the actual purpose. You receive the indicators and rules in a format your existing systems can adopt — regardless of whether you use our products. A report you can only read changes nothing about your detection.
We can tell you whether a sample belongs to a known family and what similarities exist to earlier incidents. That does not establish attribution to a particular group — one file is not enough for that. Anyone deriving a culprit from a malware sample is overstretching the finding.
Digital Forensics
Network traffic reveals what has long been deleted on endpoints. We reconstruct entry, lateral movement and exfiltratio…
ViewThere is no disk to image in the cloud. We secure logs, configuration states and identity data before the provider rete…
ViewCompany phones often hold more business secrets than any computer. We secure and examine them to an evidentiary standar…
ViewTools change, habits persist. We analyse how an attacker operates and derive where they will start next time.
ViewContact
Talk to us before somebody else does. The first conversation is free and we reply the same business day.