Method and evidence
That is the part we are here for.
Standards cover idealized situations. They do not tell you what to do when things get complicated, which is what real engagements often bring. Past that point, experience and educated judgment make an important difference to the outcome.
Every major engagement we have worked on came down to overcoming something with no obvious answer, and in a very short time. That is why no template can capture how we work.
What we deliver is competence and integrity toward our clients’ mission. This is not about producing another report. It is about leaving our clients stronger than when we arrived.
What makes the work different
01
Crown-jewel applications are usually the least examined systems in an estate. Their core logs are rarely onboarded into the SIEM and almost never included in a hunt.
We learn how the application actually works, what an attacker could do inside it, and what that would cost the business. Tooling follows the objective, never the reverse: where nothing can read a log, we build a parser for it. Instead of inheriting whatever coverage the standard log sources happened to provide, the systems carrying the most consequence get the most attention.
02
No engagement is scoped generically. The threat landscape that applies to this organization decides it: sector, geography, technology, and the adversaries realistically motivated to target it.
That keeps the scope pragmatic. Effort goes to the techniques those adversaries actually use, rather than to a checklist of everything that could theoretically happen. A compromise assessment for a Gulf energy operator and one for a European bank are not the same engagement with a different logo on the report.
03
Every finding states what was observed, what it supports, and how confident we are in it. Where the evidence does not settle a question, that is written down rather than smoothed over.
This is what makes a report hold up months later, in front of a regulator, an insurer or a board. It is also the difference between an investigation that closes and one that is quietly reopened.
04
Individual observations are only useful once they are connected. We set out what an attacker did, or could do, as one sequence across the estate, rather than leaving you a list of findings to interpret.
The recommendations that follow are shaped to your priorities and your current maturity, not selected from a catalogue, and we walk your team through them until the reasoning is clear. What you do with them afterwards is your decision.
Where your data lives
In most engagements it never does. The tooling is brought into your environment and the work is done inside it, under accounts your team issues. What leaves is the report, and the report contains only what has to be in it.
That is where their tooling runs. For regulated organizations it is not a preference to discuss. It rules the vendor out.
On premise, in your tenant, or fully isolated. No loss of depth. Residency and classification rules are fixed inputs from the first call, not obstacles.
The methodology is tuned to get maximum performance from whatever hardware is on site. Optimised Velociraptor parses a filtered MFT in about six seconds against twenty minutes or more for the stock build. At estate scale that is hours instead of weeks.
Custom parsers are built for the crown-jewel business applications other vendors cannot read, the systems that carry the most risk and the least coverage.
Existing indexed data is used where it exists. The tooling is open source, so the method is verifiable rather than a black box.
How an engagement runs
Five phases, one standard. The work is done by senior specialists, not reviewed by them.
Scoping establishes exactly what value the organization needs from the engagement, and shapes the work to deliver precisely that.
Agreed in writing before anything begins.
The environment, its technology and its threat exposure are profiled in detail before execution is planned.
Engagements are never planned on assumptions.
The work is performed by very senior specialists. Always.
Not delegated and signed off, but done by the operator whose experience the engagement was bought for.
Findings are delivered so the value is both fully understood and immediately actionable.
Technical detail the team can execute against, and an executive account that translates exposure into business terms.
Knowledge transfer, documentation and walkthroughs, with every finding carried to verified closure.
The objective is not a completed engagement but a client whose capability has grown.
Anonymized cases
Details are changed or removed where they could identify a client. The mechanism in each case is unchanged.
CASE 01
MEMORY FORENSICS
EVIDENCE CONSIDERED UNUSABLE
A compromised system had been rebooted, and the only memory image available was captured two weeks after the infection. By conventional expectation the volatile evidence was gone, and the question of who did what, and how, would stay open.
Registry keys, event log structures and MFT entries were carved directly from that memory image and reconstructed into a full account of the intrusion: the entry point, the actions taken on the system, and the attribution the investigation required. The case was closed on evidence that had already been written off.
CASE 02
REOPENED INVESTIGATION
ONE SERVER, THREE MONTHS LATER
A print server at a large European corporation had been flagged for DNS resolution attempts against a domain associated with a state-linked threat group. A specialist DFIR team, supported by a dedicated threat intelligence unit, investigated for three months and closed the case. The malware was assessed as fileless, and little was expected from further analysis of the image.
Within 48 hours, and from that single server image, the malware file itself was recovered, two separate infections were identified, two distinct lateral movement techniques were reconstructed, and hardcoded attacker infrastructure and functionality the original investigation had not surfaced were documented.
The estates this was forged on
The work behind this method was done on national telecommunications networks, regulated banks and energy estates across Europe, Saudi Arabia, the United Arab Emirates and Qatar. Environments where an intrusion is not an internal matter and where generic tooling stops being useful at the first million events.
The proactive and governance side matters as much as the response. A plan that reads well and fails on the day is worth nothing, so plans are written to be executed and then exercised until they are.