Malware Analysis
We take malware apart in an isolated environment and deliver concrete detection rules for your systems rather than a lab report.
ViewDigital Forensics
An attack leaves traces: in logs, in memory, in network traffic, on storage media. Most of them outlive it by hours. Logs roll over, virtual machines are rebuilt, buffers overflow — and with every hour spent cleaning up rather than preserving, part of the answer disappears.
We take malware apart in an isolated environment and deliver concrete detection rules for your systems rather than a lab report.
ViewNetwork traffic reveals what has long been deleted on endpoints. We reconstruct entry, lateral movement and exfiltration from captu…
ViewThere is no disk to image in the cloud. We secure logs, configuration states and identity data before the provider retention window…
ViewCompany phones often hold more business secrets than any computer. We secure and examine them to an evidentiary standard — includin…
ViewTools change, habits persist. We analyse how an attacker operates and derive where they will start next time.
ViewThe starting point
Digital forensics means securing those traces before they vanish and reconstructing the sequence from them: where the attacker got in, how long they were there, what they accessed, what they took.
The difference between “we assume it was the credentials from the phishing wave” and “we know” is not academic. It decides whether the hole is actually closed — and whether the notification to the supervisory authority holds up.

The method
Every acquisition is documented — who took custody of which medium, when, and in what state. Work happens on copies, never on the original, and every copy carries a checksum proving that nothing has changed since acquisition.
That is effort which only pays off later. A finding without that chain is worthless in a dispute: in court, towards the insurer, and towards a supervisory authority that wants to know which personal data was affected.
At the end there is a report that someone outside IT can read too: what happened, in what order, with what consequences — and which gap stays open if nothing is done.
What we do
Detailed investigation of malware to identify its origin, mode of operation and potential impact.
We take the sample apart in an isolated environment: static analysis of the binary, dynamic observation of its runtime behaviour, and comparison of the indicators against our threat database. What comes out at the end is not a lab report but a list of concrete detection rules for your systems.
In environments running Talion the same sample becomes the template for the automatic response: recognised variants are isolated before an analyst ever sees them. Strider then correlates the indicators across the whole network so a second infection does not go unnoticed. If the analysis leads to a live incident, Instant Response takes over.
Advanced techniques for reconstructing deleted or damaged data from various storage media.
Specialized investigations of smartphones and tablets to extract and analyze critical data.
Forensic analysis in complex cloud environments to secure evidence and resolve security incidents.
Rapid and thorough forensic investigations as part of the response to recent security incidents.
Professional support in the identification, collection and processing of electronic evidence for legal purposes.
Specialized forensic investigations of IoT devices and networks to uncover security vulnerabilities and attacks.
Analysis of digital traces using artificial intelligence to create detailed offender profiles and predict future attack patterns. This technology provides deeper insights into the motivations and methods of cyber criminals.
The basis for this is NeoI, our own analysis engine. It compares observed behaviour against what is normal in your environment rather than only looking for known signatures — which means an attacker using nothing but legitimate tools also stands out. The results flow back into Strider and sharpen the correlation there.
Use of AR technology for three-dimensional visualization of complex digital crime scenes. Enables investigators and decision makers to intuitively and immersively explore forensic data for better understanding and more effective decision making.
The value lies less in the technology than in making things understood: a management board, a supervisory board or a court has to be able to follow how an attacker proceeded. A spatial rendering makes attack paths visible that disappear in a table. For evidence under ISO 27001 or NIS2 we supply it alongside the classic documentation — see ISMS Implementation.
Future-proof forensic methods that are resistant even to quantum computing attacks. Ensures the long-term integrity and usability of digital evidence in a post-quantum era.
and more...
Contact
Talk to us before somebody else does. The first conversation is free and we reply the same business day.