Method and evidence

There is no recipe for the hard part.

That is the part we are here for.

Standards cover idealized situations. They do not tell you what to do when things get complicated, which is what real engagements often bring. Past that point, experience and educated judgment make an important difference to the outcome.

Every major engagement we have worked on came down to overcoming something with no obvious answer, and in a very short time. That is why no template can capture how we work.

What we deliver is competence and integrity toward our clients’ mission. This is not about producing another report. It is about leaving our clients stronger than when we arrived.

20+ Years across EMEA
10 Years in KSA, UAE and Qatar
500+ Complex incidents resolved
3 Critical sectors

What makes the work different

Four principles, applied every time.

01

Depth goes where it matters

Crown-jewel applications are usually the least examined systems in an estate. Their core logs are rarely onboarded into the SIEM and almost never included in a hunt.

We learn how the application actually works, what an attacker could do inside it, and what that would cost the business. Tooling follows the objective, never the reverse: where nothing can read a log, we build a parser for it. Instead of inheriting whatever coverage the standard log sources happened to provide, the systems carrying the most consequence get the most attention.

02

Scoped against relevant threats

No engagement is scoped generically. The threat landscape that applies to this organization decides it: sector, geography, technology, and the adversaries realistically motivated to target it.

That keeps the scope pragmatic. Effort goes to the techniques those adversaries actually use, rather than to a checklist of everything that could theoretically happen. A compromise assessment for a Gulf energy operator and one for a European bank are not the same engagement with a different logo on the report.

03

Conclusions carry their evidence

Every finding states what was observed, what it supports, and how confident we are in it. Where the evidence does not settle a question, that is written down rather than smoothed over.

This is what makes a report hold up months later, in front of a regulator, an insurer or a board. It is also the difference between an investigation that closes and one that is quietly reopened.

04

One account, not a list of findings

Individual observations are only useful once they are connected. We set out what an attacker did, or could do, as one sequence across the estate, rather than leaving you a list of findings to interpret.

The recommendations that follow are shaped to your priorities and your current maturity, not selected from a catalogue, and we walk your team through them until the reasoning is clear. What you do with them afterwards is your decision.

Where your data lives

Evidence does not have to leave your estate.

In most engagements it never does. The tooling is brought into your environment and the work is done inside it, under accounts your team issues. What leaves is the report, and the report contains only what has to be in it.

Most IR vendors ship your data to their cloud.

That is where their tooling runs. For regulated organizations it is not a preference to discuss. It rules the vendor out.

We bring the analysis to the data.

On premise, in your tenant, or fully isolated. No loss of depth. Residency and classification rules are fixed inputs from the first call, not obstacles.

Speed is what makes on premise practical.

The methodology is tuned to get maximum performance from whatever hardware is on site. Optimised Velociraptor parses a filtered MFT in about six seconds against twenty minutes or more for the stock build. At estate scale that is hours instead of weeks.

Any log, however exotic.

Custom parsers are built for the crown-jewel business applications other vendors cannot read, the systems that carry the most risk and the least coverage.

No agents, no new licences.

Existing indexed data is used where it exists. The tooling is open source, so the method is verifiable rather than a black box.

parse_mft_parallel · live run log
$MFT 5.39 GB · 5,650,177 ENTRIES · 8 WORKERS
TimestampMessage
19:33:09.853Zmft live-parallel: \\.\C: $MFT = 5785780224 bytes (~5650176 entries) in 25 run(s), average run 220 MB, no RAM copy, one device handle per worker
19:33:09.853Zparse_mft_parallel: decoding entries [0, 5650177) (record_size=1024, accessor="ntfs", extended=true)
19:33:09.853Zparse_mft_parallel: $MFT 5.39 GB, budget 30.37 GB (80% of 37.96 GB available); uncapped peak would be 10.35 GB; 25 run(s) averaging 220 MB → gear 3:device-shards, workers 0, soft limit none
19:33:09.853Zparse_mft_parallel: gear 3:device-shards, 8 worker(s) over entries [0,5650177)
19:33:13.849Zparse_mft_parallel: WORKER 1 entries [706273,1412545) → 161 rows
19:33:14.116Zparse_mft_parallel: WORKER 3 entries [2118817,2825089) → 29 rows
19:33:14.380Zparse_mft_parallel: WORKER 5 entries [3531361,4237633) → 14 rows
19:33:14.402Zparse_mft_parallel: WORKER 0 entries [0,706273) → 280 rows
19:33:14.409Zparse_mft_parallel: WORKER 4 entries [2825089,3531361) → 3 rows
19:33:14.818Zparse_mft_parallel: WORKER 7 entries [4943905,5650177) → 7 rows
19:33:14.878Zparse_mft_parallel: WORKER 6 entries [4237633,4943905) → 410 rows
19:33:15.732Zparse_mft_parallel: WORKER 2 entries [1412545,2118817) → 82 rows
19:33:15.732Zparse_mft_parallel: fan-out complete, 8 worker(s), 986 rows total
Filtered timeline from a 5.4 GB $MFT in 5.88s
Same analysis with the stock tool: over 1300s

How an engagement runs

Senior from scoping to handover.

Five phases, one standard. The work is done by senior specialists, not reviewed by them.

PHASE 01

Scope

Scoping establishes exactly what value the organization needs from the engagement, and shapes the work to deliver precisely that.

Agreed in writing before anything begins.

PHASE 02

Deep profile and planning

The environment, its technology and its threat exposure are profiled in detail before execution is planned.

Engagements are never planned on assumptions.

PHASE 03

Execute

The work is performed by very senior specialists. Always.

Not delegated and signed off, but done by the operator whose experience the engagement was bought for.

PHASE 04

Report

Findings are delivered so the value is both fully understood and immediately actionable.

Technical detail the team can execute against, and an executive account that translates exposure into business terms.

PHASE 05

Enable

Knowledge transfer, documentation and walkthroughs, with every finding carried to verified closure.

The objective is not a completed engagement but a client whose capability has grown.

Anonymized cases

Two cases that turned on evidence others had discounted.

Details are changed or removed where they could identify a client. The mechanism in each case is unchanged.

CASE 01

MEMORY FORENSICS

EVIDENCE CONSIDERED UNUSABLE

An answer carved from evidence considered unusable.

A compromised system had been rebooted, and the only memory image available was captured two weeks after the infection. By conventional expectation the volatile evidence was gone, and the question of who did what, and how, would stay open.

Registry keys, event log structures and MFT entries were carved directly from that memory image and reconstructed into a full account of the intrusion: the entry point, the actions taken on the system, and the attribution the investigation required. The case was closed on evidence that had already been written off.

14 days After infection
1 Memory image, post-reboot
Full Timeline reconstructed

CASE 02

REOPENED INVESTIGATION

ONE SERVER, THREE MONTHS LATER

One server, after a three-month investigation had closed.

A print server at a large European corporation had been flagged for DNS resolution attempts against a domain associated with a state-linked threat group. A specialist DFIR team, supported by a dedicated threat intelligence unit, investigated for three months and closed the case. The malware was assessed as fileless, and little was expected from further analysis of the image.

Within 48 hours, and from that single server image, the malware file itself was recovered, two separate infections were identified, two distinct lateral movement techniques were reconstructed, and hardcoded attacker infrastructure and functionality the original investigation had not surfaced were documented.

<48h To first findings
1 Server image
2 Infections identified
2 Lateral movement paths

The estates this was forged on

Two decades of estates, and a decade of other people’s escalations.

The work behind this method was done on national telecommunications networks, regulated banks and energy estates across Europe, Saudi Arabia, the United Arab Emirates and Qatar. Environments where an intrusion is not an internal matter and where generic tooling stops being useful at the first million events.

The proactive and governance side matters as much as the response. A plan that reads well and fails on the day is worth nothing, so plans are written to be executed and then exercised until they are.

Telecommunications National-scale estates where an intrusion is a matter of public consequence, and where scale itself defeats generic tooling.
Banking and financial services Regulated environments where evidence handling, auditability and defendable reporting matter as much as the technical finding itself.
Oil and gas Estates where availability and safety constraints rule out conventional approaches, and where OT and IT exposure have to be assessed together.

NEXT / CAPABILITY

Solutions

The four categories and the eight named engagements inside them.

NEXT / SCOPING

Engage

Describe the situation. If we are the wrong firm for it, we will say so.