Method and evidence
The hard part has no recipe. That is the part the firm is here for.
Standards cover idealized situations. They do not tell you what to do when things get complicated, which is what real engagements often bring. Past that point, experience and educated judgment make an important difference to the outcome.
Every major engagement in the firm’s history came down to overcoming something with no obvious answer, and in a very short time. That is why no template can capture how the work is done.
What the firm delivers is competence and integrity toward the client’s mission. The report is the by-product. The point is a client left stronger than before the engagement started.
What makes the work different
Four principles, applied every time.
01
Depth goes where it matters
Crown-jewel applications are usually the least examined systems in an estate. Their core logs are rarely onboarded into the SIEM and almost never included in a hunt.
The work starts by learning how the application actually works, what an attacker could do inside it, and what that would cost the business. Tooling follows the objective, never the reverse: where nothing can read a log, a parser gets written for it. Instead of inheriting whatever coverage the standard log sources happened to provide, the systems carrying the most consequence get the most attention.
02
Scoped against relevant threats
No engagement is scoped generically. The threat landscape that applies to this organization decides it: sector, geography, technology, and the adversaries realistically motivated to target it.
That keeps the scope pragmatic. Effort goes to the techniques those adversaries actually use, rather than to a checklist of everything that could theoretically happen. A compromise assessment for a Gulf energy operator and one for a European bank are not the same engagement with a different logo on the report.
03
Conclusions carry their evidence
Every finding states what was observed, what it supports, and the confidence attached to it. Where the evidence does not settle a question, that is written down rather than smoothed over.
This is what makes a report hold up months later, in front of a regulator, an insurer or a board. It is also the difference between an investigation that closes and one that is quietly reopened.
04
One account, not a list of findings
Individual observations are only useful once they are connected. The report sets out what an attacker did, or could do, as one sequence across the estate, rather than leaving you a list of findings to interpret.
The recommendations that follow are shaped to your priorities and your current maturity, not selected from a catalog, and the consultant walks your team through them until the reasoning is clear. What you do with them afterwards is your decision.
Where your data lives
Evidence does not have to leave your estate.
In most engagements it never does. The tooling is brought into your environment and the work is done inside it, under accounts your team issues. What leaves is the report, and the report contains only what has to be in it.
That is where their tooling runs. For regulated organizations it is not a preference to discuss. It rules the vendor out.
On premise, in your tenant, or fully isolated. No loss of depth. Residency and classification rules are fixed inputs from the first call, not obstacles.
The methodology is tuned to get maximum performance from whatever hardware is on site. Optimised Velociraptor parses a filtered MFT in about six seconds against twenty minutes or more for the stock build. At estate scale that is hours instead of weeks.
Custom parsers are built for the crown-jewel business applications other vendors cannot read, the systems that carry the most risk and the least coverage.
Existing indexed data is used where it exists. The tooling is open source, so the method is verifiable rather than a black box.
Same analysis with the stock tool: over 1300s
How an engagement runs
Senior from scoping to handover.
Five phases, one standard. The work is done by senior specialists, not reviewed by them.
Scope
Scoping establishes exactly what value the organization needs from the engagement, and shapes the work to deliver precisely that.
Agreed in writing before anything begins.
Deep profile and planning
The environment, its technology and its threat exposure are profiled in detail before execution is planned.
Engagements are never planned on assumptions.
Execute
The work is performed by very senior specialists. Always.
Not delegated and signed off, but done by the operator whose experience the engagement was bought for.
Report
Findings are delivered so the value is both fully understood and immediately actionable.
Technical detail the team can execute against, and an executive account that translates exposure into business terms.
Enable
Knowledge transfer, documentation and walkthroughs, with every finding carried to verified closure.
The objective is not a completed engagement but a client whose capability has grown.
Anonymized cases
Two cases that turned on evidence others had discounted.
Details are changed or removed where they could identify a client. The mechanism in each case is unchanged.
CASE 01
MEMORY FORENSICS
EVIDENCE CONSIDERED UNUSABLE
An answer carved from evidence considered unusable.
A compromised system had been rebooted, and the only memory image available was captured two weeks after the infection. By conventional expectation the volatile evidence was gone, and the question of who did what, and how, would stay open.
Registry keys, event log structures and MFT entries were carved directly from that memory image and reconstructed into a full account of the intrusion: the entry point, the actions taken on the system, and the attribution the investigation required. The case was closed on evidence that had already been written off.
CASE 02
REOPENED INVESTIGATION
ONE SERVER, THREE MONTHS LATER
One server, after a three-month investigation had closed.
A print server at a large European corporation had been flagged for DNS resolution attempts against a domain associated with a state-linked threat group. A specialist DFIR team, supported by a dedicated threat intelligence unit, investigated for three months and closed the case. The malware was assessed as fileless, and little was expected from further analysis of the image.
Within 48 hours, and from that single server image, the malware file itself was recovered, two separate infections were identified, two distinct lateral movement techniques were reconstructed, and hardcoded attacker infrastructure and functionality the original investigation had not surfaced were documented.
The estates this was forged on
Two decades of estates, and a decade of other people’s escalations.
The work behind this method was done on national telecommunications networks, regulated banks and energy estates across Europe, Saudi Arabia, the United Arab Emirates and Qatar. Environments where an intrusion is not an internal matter and where generic tooling stops being useful at the first million events.
The proactive and governance side matters as much as the response. A plan that reads well and fails on the day is worth nothing, so plans are written to be executed and then exercised until they are.