⚠Incident Triage & Initial Assessment
Validate the incident, identify immediate risk, prioritise volatile evidence and provide proportionate containment recommendations.
◉Compromise Assessment
Hunt for unauthorised access, persistence, credential misuse and lateral movement across endpoints, identity, cloud and network evidence.
⌕Root-Cause Analysis
Identify the initial access route, reconstruct attacker progression and distinguish the root cause from contributing control failures.
✉Business Email Compromise
Investigate mailbox access, malicious rules, OAuth consent, session abuse, impersonation and payment-diversion activity.
▤Database Intrusion
Examine authentication, queries, privilege changes, operating-system execution and potential access to business records.
☁Cloud Forensics
Reconstruct identity and API activity across AWS, Azure and Google Cloud, including storage access and temporary credential abuse.
⌘Application, API & Web Forensics
Rebuild exploit paths from web, proxy and application evidence, and trace access into databases and internal services.
▣Endpoint & Server Forensics
Analyse Windows, Linux and macOS evidence for process execution, persistence, credential theft, malware and data staging.
▯Smartphone Forensics
Investigate supported mobile devices for suspicious applications, account activity, communications, spyware indicators and data loss.
▰Payment Data & PCI Incidents
Assess payment applications and cardholder environments for unauthorised access, web skimming and payment-data exposure.
♙Identity & Active Directory
Investigate compromised accounts, privilege escalation, token abuse, domain-controller access and hybrid identity persistence.
✣Ransomware & Malware
Determine initial access, propagation, security-control interference, encryption impact and whether data was stolen first.
◎Insider Threat
Correlate user, endpoint, cloud, email and application evidence to distinguish normal work from deliberate misuse or theft.
⇧Data Exfiltration Assessment
Separate confirmed transfer from staging, possible access and evidential uncertainty across host, network and cloud sources.
⌁Vulnerability Exploitation
Determine whether a vulnerable service was exploited, what commands ran and whether the attacker reached downstream systems.
✓Forensic Readiness
Assess logging, retention, time synchronisation, evidence access and preservation procedures before an incident tests them.
◈Cyber Tabletop Exercises
Test technical, executive, legal and communications decisions through realistic, organisation-specific incident scenarios.