Malware Analysis
We take malware apart in an isolated environment and deliver concrete detection rules for your systems rather than a la…
ViewDigital Forensics
An attacker can delete traces on a machine. The traffic they generated while doing so cannot be taken back. That is why the network is often the most dependable source once the endpoints have already been tidied up.

The basis
In most cases full packet captures are not available. That is not a blocker — from flow and DNS data the sequence of events can as a rule be reconstructed dependably.
Full packet captures where they exist — the most complete but rarest source
who talked to whom, when and for how long
often the first pointer to command-and-control servers
destinations, data volumes, blocked attempts
sign-ins, times, source addresses
The result
Timeline of the attack from first contact to last access
Identification of the command infrastructure and how it was reached
Proof or exclusion of data exfiltration, with an order of magnitude
Affected systems, including those with no conspicuous endpoint traces
Detection rules for a repeat case
The time pressure
Whether personal data left the organization decides the reporting obligation under the GDPR — and that leaves 72 hours. Network forensics is often the only way to answer that question dependably instead of reporting as a precaution. So we order the analysis around that deadline.
Beforehand
How good a later investigation turns out is decided before the incident: is flow data collected at all? How long is it retained? Are the clocks in sync? We check that as part of the ISMS build-up and set up collection so that it holds when it matters. Ongoing analysis then happens in Strider.
FAQ
As a rule, yes. Full captures are almost never available, so an investigation relies mostly on flow, DNS, proxy and firewall logs anyway. From those the sequence of events can usually be reconstructed dependably. What is missing is the content of the connections — not the connections themselves.
Often yes, and that is usually the decisive question. Flow data shows how much went in which direction; DNS and proxy show where to. What normally stays open without a full capture is the exact content. We write into the report what is evidenced and what is not — presenting a presumption as a finding does not help you with the notification.
In practice, weeks to months pass between initial access and discovery. Logs overwritten after two weeks no longer cover the beginning of the incident. We recommend retention well beyond that — the exact period we settle against your data protection requirements.
A timeline is built by laying events from different sources side by side. If clocks differ by minutes, the order shifts — and with it the statement about what was cause and what was effect. In court such a timeline is attackable. Time synchronisation costs nothing and decides retrospectively whether the evidence holds.
No. We work on copies of the logs, not on the systems themselves. Where a capture has to be set up, it is done through a mirror port or a passive tap — the traffic continues unchanged.
Digital Forensics
We take malware apart in an isolated environment and deliver concrete detection rules for your systems rather than a la…
ViewThere is no disk to image in the cloud. We secure logs, configuration states and identity data before the provider rete…
ViewCompany phones often hold more business secrets than any computer. We secure and examine them to an evidentiary standar…
ViewTools change, habits persist. We analyse how an attacker operates and derive where they will start next time.
ViewContact
Talk to us before somebody else does. The first conversation is free and we reply the same business day.