// digital forensics & incident response
IncidentResponse
When you've been breached, most firms tell you what happened. We reconstruct how the attacker got in, because breaking in is our day job, and then we re-attack the entry point to prove the fix holds.
Active incident? Say so in your message. It goes to the front of the queue.
attacker_activity // rebuilt from forensic artifacts
- T-14d 03:12Initial access: exposed VPN appliance, valid creds, no MFA
- T-13d 11:38Lateral movement via cached local admin credentials
- T-09d 22:04Persistence: rogue OAuth grant + scheduled task
- T-02d 04:51Staging: 40 GB archived to attacker cloud storage
- T-0 09:47Exfiltration detected. Investigation begins.
// what it is
Forensics with an attacker's eye
Containment tells you the incident is over. It doesn't tell you why it happened, and until you know exactly how the attacker got in, you're one redeploy away from hosting them again. Every investigation we run has to answer three questions, and we don't consider it finished until all three have evidence behind them.
We run scoped investigation engagements, during an active incident or after the dust settles, with senior US-based responders under NDA. An investigations practice, not a monitoring retainer.
What happened?
The forensic record: every system touched, every account used, every byte staged and moved.
How did they get in?
The entry vector, reproduced by our offensive team with their own hands. Demonstrated, not inferred.
Can it happen again?
Not through that door. We harden the weakness class, then re-attack the original path to prove it.
// when to call us
What we investigate
From live intrusions to quiet suspicions. If there's an attacker in the story, we can reconstruct their steps.
- IR-01Active Compromise
An attacker is in your environment right now. We help you scope, contain, and evict without tipping them off before you're ready.
- IR-02Ransomware & Extortion
Encryption events and data-theft extortion. We establish what was taken, how they got in, and whether they still have a way back inside.
- IR-03BEC & Account Takeover
Compromised mailboxes, fraudulent wires, and OAuth abuse. We trace the session history, the rules they planted, and everything they touched.
- IR-04Web App & Cloud Breaches
Exploited applications, leaked keys, and cloud tenant intrusions. These are the environments our offensive work lives in every day.
- IR-05Insider Events
Departing employees, data theft, and misuse of privileged access. Discreet investigation with evidence handling that holds up.
- IR-06Compromise Assessment
Something feels wrong but nothing has triggered. We hunt for evidence of compromise and either find the intrusion or give you real confidence.
$ ./how-it-works
From breach to proven root cause
A forensic investigation that ends the way our pentests do: with evidence, a fix path, and verification.
- 01
Triage & Stabilize
Evidence preservedA senior responder scopes the situation fast: what's affected, what evidence exists, what must be preserved, and what needs containment first.
- 02
Collect Forensics
Chain of custodyDisk and memory acquisition, log collection, and cloud audit trails, gathered with chain-of-custody discipline so findings hold up later.
- 03
Reconstruct the Timeline
The attacker's storyWe piece the artifacts into the attacker's story: initial access, lateral movement, persistence, staging, and exfiltration, hour by hour.
- 04
Prove the Root Cause
Reproduced, not inferredThis is where our offensive DNA matters. We reproduce the entry path ourselves, whether it was an exploit, a misconfiguration, or a stolen credential, so root cause is demonstrated rather than guessed.
- 05
Fix & Verify
Door provably closedYou get an engineer-ready remediation sequence for the weakness class, then we re-attack the original path to confirm the door is actually closed.
// why platformsecurity
Most IR stops at containment. We don't.
Contains the incident, closes the ticket, and moves on to the next client in the queue.
Treats containment as the halfway point. The engagement isn't done until root cause is proven and the fix is verified.
Reports end at patient zero: "initial access via phishing, probably."
Reproduces the actual entry path with our own hands, so "how it happened" is a demonstrated fact.
Analysts read artifacts against a playbook of known patterns.
People who build exploit chains for a living read the same artifacts, and recognize tradecraft playbooks miss.
Remediation arrives as a generic hardening checklist appended to the report.
A prioritized, sequenced fix path for the weakness class, written for the engineers who will ship it.
The fix is assumed to work because the alert stopped firing.
We go back and re-attack the original entry vector. If it's still open, you hear it from us and not from them.
The best incident is the one that never lands. Before something goes wrong, or once the dust settles, pressure-test the same paths attackers use with red teaming and penetration testing.
$ cat deliverables.txt
What you get
- 01A forensic timeline of attacker activity from initial access to last observed action, backed by evidence
- 02Root-cause analysis of the entry vector, reproduced by our offensive team rather than inferred
- 03Full scope of compromise (affected systems, accounts, and data) with an IOC set your team can hunt on
- 04Containment and eradication guidance sequenced so you don't tip off an attacker who's still inside
- 05A prioritized hardening roadmap that addresses the class of weakness, not just the instance
- 06Executive summary and technical report written to hold up with your board, insurer, and counsel
- 07Optional verification retest: we re-attack the original entry path to prove it's closed
// move fast, move smart
Breached? Get the full story.
Tell us what you're seeing, even if it's just a bad feeling. A senior responder reviews every message, active incidents go to the front of the queue, and an NDA is available before you share anything sensitive.