Reactive engagement / 05

Digital Forensics and Incident Response.

Where the hard cases land. Reconstruct what happened even when the evidence is cold, then contain, eradicate and recover.

During an incident the questions are simple and the answers are not. What got in, how far did it go, what did it take, and is it still here. Answering them takes evidence, and evidence degrades from the moment the incident starts.

When another team has already closed a case, this is often the second call, and the one that resolves it.

Incident response engagements are taken from Switzerland, across Europe and the Gulf, and the first call is with the person who will do the work.

40-80h Live incident, excluding the report
8-16h Final report, shaped to your questions
32h+ Post-mortem investigation, report included
Daily Technical updates during an engagement
[ HOW TO START ]

Call now, or agree the terms first.

Emergency response and the retainer are both available directly. The difference on the day is everything in the table below.

A

Emergency response

Emergency incident response, for when something is happening now. Rapid deployment, containment, forensic analysis and guided recovery for ransomware, insider activity, data breach and targeted intrusion. If something is happening now, call rather than write.

What it assumes
Scope, access and communication protocols are established at the start of the engagement, while the incident is running.
B

DFIR Retainer

Secures priority access to incident response before you need it, with the environment already understood and the communication protocols agreed in advance. Retainer hours not consumed by incidents are not lost. They convert to other consulting work.

What it assumes
A scoping conversation now, so that on the day of an incident the only open question is the incident itself.
[ THREE WAYS THIS GOES ]

Same team. Not the same outcome.

Both routes on offer reach the same people in Zug and the same method. What differs is everything that happens before the call, and the first hours of an incident are where that difference is paid back or paid for. The middle column is here because it is the arrangement most often mistaken for one of the other two.

Emergency IRcalled on the dayCyber insurancefor comparison onlyDFIR Retaineragreed before anything happens
Availability on the daySubject to available capacity on the day. Loaded periods are real, and the end of the year is the worst of them.Funded once the claim is opened, but the responder comes from a panel the insurer chooses, and that panel can change between renewals.A response SLA, written into the contract, honoured by the team that already knows the environment.
The first hoursIt starts with a call and an email: a long list of logs and data to be collected, then transferred, then processed and then analyzed. Some of the answers requested depend on people who may be at home, on leave, or already busy recovering.The same, once a claim has been opened and a firm assigned.It starts with analysis. Velociraptor is already deployed and the relevant evidence is already reachable, so the first hours are spent reading it rather than asking for it.
Progress 24 hours after kick-offDaily updates start immediately, but the first is largely a list of what is still missing or blocking the investigation, and a few generic security best practices. Nothing has been established as clean yet, so recovery cannot safely start.The same, and the clock starts only once the claim is opened and a firm is assigned, so hour 24 of the incident is not hour 24 of the investigation.The first daily update already carries findings, and immediate containment and hardening steps to allow the recovery of critical business applications. Because collection already spans the estate, it can also say where the compromise is not, which is what makes a restart possible.
Knowing what normal looks likeNothing is known in advance. The first days go on learning the estate, while the internal team is also trying to recover.Whoever turns up has never seen the estate. What would look wrong to someone who knows it goes past unnoticed.Onboarding maps the account naming conventions, the network, and where the crown jewels sit, resynchronised every three months. What looks wrong is recognized as wrong.
What the investigation can answerWhatever the logs that happen to exist allow. In practice they rarely cover every question the investigation needs to ask, and some end with no answer at all.The same. A policy funds the investigation. It does not change what evidence exists to investigate.The log sources and audit settings an investigation depends on are specified at the start, and checked if the first months stay quiet. The questions have answers because the evidence was made to exist.
Preventing incidentsOut of scope. There is no relationship before the call, and no view of the environment to improve.Some policies include pre-breach services, but none of it is built around the firm that will actually turn up, because that firm is not known in advance.Included. The environment is reviewed and what makes a large incident likely is fixed. It consumes hours on purpose: a large incident answered well is still a failure of prevention.
What the money buysThe emergency hour costs far more than the retainer hour.A premium that pays out against loss. It is not hours that can be spent.The standard rate, on hours agreed in advance.
If the year stays quietNothing was spent, and nothing changed.The premium is spent, which is what a premium is for. Nothing about readiness changed.Hours not consumed by incidents are not lost. They go to the visibility review, the hardening backlog, or other consulting work chosen by the client.

What the work covers

The work, in the order that limits damage.

Containment and evidence preservation pull against each other. Deciding that trade-off correctly, under time pressure, is most of the job.

01

Incident Commander

One person accountable for the whole response, with the authority to gate it. Workstreams run in parallel, decisions are logged, and the executive briefing comes from a single voice.

Large incidents fail on coordination more often than on technique. Where several teams and vendors are on site, the work is keeping investigation, recovery, monitoring and hardening from pulling against each other, and holding the gate that stops a system being restored before it has been cleared.

02

Rapid containment

Immediate action to stop the incident spreading: isolating affected systems, disabling compromised accounts and applying emergency measures.

The order matters. Pulling a machine off the network destroys volatile evidence that may be the only record of how the attacker got in, so containment steps are sequenced against what still needs to be captured.

03

Forensic analysis

Disk, memory and cloud evidence collected and analyzed to establish root cause, attack vectors and the true extent of the compromise, then assembled into one sequence of events across the estate.

A list of findings is not an account of an incident. Each step carries the artifact that supports it and a stated confidence level, including where the evidence is partial, degraded or was written off as unrecoverable. Evidence others consider unusable is regularly where the answer is found.

04

Recovery and hardening

A remediation plan executed to eradicate the threat and return operations to a secure state, followed by a review that turns the incident into improvement.

Recovery without eradication returns you to the same position with less evidence. The route that was used is closed before systems come back, and the review says what to change so it stays closed.

How an engagement runs

Five phases, from the call to the review.

Read it left to right: two steps in sequence, four streams in parallel, a coordinated eviction, then the review. The clock above them is the evidence, and it starts running before the response does.

EVIDENCE AVAILABILITY falling from the first minute of the incident MEMORY DFIR ARTIFACTS CHANGE LOGS ROTATE FREE SPACE REUSED INCIDENT RESPONSE PHASES sequential where it has to be, parallel everywhere else PHASE 01 Activation and triage scope, severity PHASE 02 Initial containment stop the damage, not the actor PHASE 03 · A Enhanced threat detection see re-entry PHASE 03 · B Hardening of the environment clean ground for recovery PHASE 03 · C Forensic analysis what happened PHASE 03 · D Coordination of initial recovery restore only clean PHASE 04 · A Full containment every path at once PHASE 04 · B Eradication and full recovery remove and verify PHASE 05 Post-incident review close the path Modern incident response runs on efficiency and pragmatism. The standard IR phases in order work only for simple incidents. Efficiency because the actor is still working. Pragmatism because restoring business operations cannot wait for the full picture.
PHASE 01

Activation and triage

On notification the response activates and a rapid triage establishes the scope and severity of the incident.

Effort goes where it changes the outcome.

PHASE 02

Initial containment

Stop the bleeding. Enough action to halt active damage, balanced against the evidence the investigation still depends on.

Where damage is already running, speed wins. Where an actor has been quiet for months, it does not, and containment waits.

PHASE 03 · IN PARALLEL

Four streams, one command

Enhanced threat detection. Hardening of the environment. Forensic analysis. Coordination of initial recovery.

They are not independent tracks. Analysis produces the indicators detection hunts on, detection proves whether hardening held, and neither lets recovery restore a system that is not clean.

PHASE 04 · IN PARALLEL

Full containment, eradication and recovery

The eviction is held back until the four streams have made it safe, then executed as one coordinated action across the estate.

Taken piecemeal it tells the actor what you know and lets them re-enter through the access you have not found yet.

PHASE 05

Post-incident review

Once the incident is resolved, a review establishes what happened, how the response performed, and what to change so the same path is closed.

What you receive

Four documents, written to be used.

Every conclusion states what was observed, what it supports, and the confidence attached to it. Where the evidence does not settle a question, that is written down.

Incident report The nature of the incident, the response actions taken and the impact on the organization, with a timeline of events and the evidence supporting it.
Forensic analysis report Where the case requires it, a full forensic account of the evidence, the methods applied and the conclusions drawn, written to withstand external review.
Containment and remediation plan Specific recommendations for addressing the vulnerabilities exploited, recovering systems, and closing the route that was used.
Post-incident recommendations Lessons learned converted into actions that raise the security posture, so the engagement leaves the organization stronger than it found it.

Anonymized case

Three vendors, one destructive attack, and nobody holding the whole picture.

Client, country, sector detail, dates and attribution are removed. The mechanism, the sequence and the decisions are unchanged.

CASE 01

INCIDENT COMMAND

DESTRUCTIVE ATTACK, STATE-LINKED ACTOR

NIST SP 800-61R3 / ICS-214 / ISO 27035

The response was designed to work without the answer it depended on.

A government authority in the Middle East, operator of critical public infrastructure, lost its public-facing services overnight. Wiper malware had been pushed to every domain-joined system through a weaponised Group Policy object. More than fifteen servers were destroyed and over a thousand endpoints were targeted. Hours before the wiper ran, the primary backup appliance had been logged into from a compromised jump server and wiped, so that recovery would fail even if the malware was caught.

Three organizations were already on site. One owned the forensic investigation, one owned recovery, the internal SOC owned monitoring, and none of them were on a shared call. Recovery had begun restoring systems that had never been imaged. The investigation could not confirm the attacker was evicted, and the business could not wait for it to. I was brought in as Incident Commander to make the response work under that uncertainty instead of pausing for it.

Four workstreams, one command. A forensic clearance gate between investigation and recovery, so nothing was restored or rebuilt before imaging on that system was confirmed, and nothing returned to production without EDR reporting to the SOC. Every hardening measure paired with a detection use case, so an attempt to work around a control that had just been closed would surface instead of passing silently. When the intrusion turned out to be an eighteen-month campaign with multiple independent backdoors, the recovery sequence changed repeatedly, and the command structure is what let it change without the response coming apart.

Communications ran on the same discipline. One daily executive briefing, one voice to the board, the regulator and legal counsel, and no technical team speaking to any of them directly. Regulatory notification was carried as a formal decision with a legal clock running against it. Every line of that briefing was marked confirmed, assessed or unknown, and the unknowns stayed visible.

By day seventeen all twenty-eight applications in the two highest-priority tiers were restored, public-facing services among them.

18 months Undetected dwell before detonation
<2h VPN account to Domain Administrator
4 Workstreams under one command
28 / 28 Priority tier 1 and 2 applications restored

Who this is for

Where the call usually comes from.

Active incident Organizations in an active breach that need senior hands on it today.
Unsatisfying closure Teams holding a case that was closed without a satisfying answer.
Board and legal Boards, regulators and legal counsel needing findings that will survive scrutiny.
Crisis management Executives who need one voice to the board, the regulator and the press while the technical response runs.
Ahead of the day Organizations that would rather agree terms and access now than negotiate them during a crisis.

What is needed to scope a program

These are enough to produce a price.

Environment size How many endpoints and how many users.
Microsoft 365 Whether it is in use, and for how many users.
Internet-facing applications A count of the web applications exposed to the internet.
Telemetry What logging exists today and how long it is retained.

The method, in the open

How the evidence in these cases actually works.

Evidence of execution Proving a program ran on Windows, source by source, with what each one contains and what it will support in a report.
NTFS timestamps What file timestamps mean, and where a tool that wrote them leaves a mark the file system would not.
Deleted files What survives a deletion on NTFS, which is most of the reason a case that looks closed usually is not.

NEXT / CAPABILITY

Solutions

The four categories and the eight named engagements inside them.

NEXT / SCOPING

Engage

Describe the situation. The call is with the consultant who would run the assessment, not a salesperson.