EN

Digital Forensics

Digital Forensics

An attack leaves traces: in logs, in memory, in network traffic, on storage media. Most of them outlive it by hours. Logs roll over, virtual machines are rebuilt, buffers overflow — and with every hour spent cleaning up rather than preserving, part of the answer disappears.

01

Malware Analysis

We take malware apart in an isolated environment and deliver concrete detection rules for your systems rather than a lab report.

View
02

Network Forensics

Network traffic reveals what has long been deleted on endpoints. We reconstruct entry, lateral movement and exfiltration from captu…

View
03

Cloud Forensics

There is no disk to image in the cloud. We secure logs, configuration states and identity data before the provider retention window…

View
04

Mobile Forensics

Company phones often hold more business secrets than any computer. We secure and examine them to an evidentiary standard — includin…

View
05

Behavioural Forensics

Tools change, habits persist. We analyse how an attacker operates and derive where they will start next time.

View
01

The starting point

After an incident, what counts is what can be proven

Digital forensics means securing those traces before they vanish and reconstructing the sequence from them: where the attacker got in, how long they were there, what they accessed, what they took.

The difference between “we assume it was the credentials from the phishing wave” and “we know” is not academic. It decides whether the hole is actually closed — and whether the notification to the supervisory authority holds up.

A dark laboratory surface under raking light. Only where the narrow beam passes do fine traces on the surface become visible.
02

The method

Evidentiary means: verifiable by a third party

Every acquisition is documented — who took custody of which medium, when, and in what state. Work happens on copies, never on the original, and every copy carries a checksum proving that nothing has changed since acquisition.

That is effort which only pays off later. A finding without that chain is worthless in a dispute: in court, towards the insurer, and towards a supervisory authority that wants to know which personal data was affected.

At the end there is a report that someone outside IT can read too: what happened, in what order, with what consequences — and which gap stays open if nothing is done.

03

What we do

Services

02

Data recovery

Advanced techniques for reconstructing deleted or damaged data from various storage media.

06

Incident response forensics

Rapid and thorough forensic investigations as part of the response to recent security incidents.

07

E-discovery services

Professional support in the identification, collection and processing of electronic evidence for legal purposes.

08

IoT forensics

Specialized forensic investigations of IoT devices and networks to uncover security vulnerabilities and attacks.

09

AI-assisted behavioral forensics

Analysis of digital traces using artificial intelligence to create detailed offender profiles and predict future attack patterns. This technology provides deeper insights into the motivations and methods of cyber criminals.

The basis for this is NeoI, our own analysis engine. It compares observed behaviour against what is normal in your environment rather than only looking for known signatures — which means an attacker using nothing but legitimate tools also stands out. The results flow back into Strider and sharpen the correlation there.

10

Augmented reality forensics visualization

Use of AR technology for three-dimensional visualization of complex digital crime scenes. Enables investigators and decision makers to intuitively and immersively explore forensic data for better understanding and more effective decision making.

The value lies less in the technology than in making things understood: a management board, a supervisory board or a court has to be able to follow how an attacker proceeded. A spatial rendering makes attack paths visible that disappear in a table. For evidence under ISO 27001 or NIS2 we supply it alongside the classic documentation — see ISMS Implementation.

11

Quantum-resistant evidence preservation

Future-proof forensic methods that are resistant even to quantum computing attacks. Ensures the long-term integrity and usability of digital evidence in a post-quantum era.

and more...

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.