// digital forensics & incident response

IncidentResponse

When you've been breached, most firms tell you what happened. We reconstruct how the attacker got in, because breaking in is our day job, and then we re-attack the entry point to prove the fix holds.

Active incident? Say so in your message. It goes to the front of the queue.

incident_timelinereconstructed

attacker_activity // rebuilt from forensic artifacts

  • T-14d 03:12Initial access: exposed VPN appliance, valid creds, no MFA
  • T-13d 11:38Lateral movement via cached local admin credentials
  • T-09d 22:04Persistence: rogue OAuth grant + scheduled task
  • T-02d 04:51Staging: 40 GB archived to attacker cloud storage
  • T-0 09:47Exfiltration detected. Investigation begins.
ROOT CAUSEentry path reproduced · remediated · re-attacked

// what it is

Forensics with an attacker's eye

Containment tells you the incident is over. It doesn't tell you why it happened, and until you know exactly how the attacker got in, you're one redeploy away from hosting them again. Every investigation we run has to answer three questions, and we don't consider it finished until all three have evidence behind them.

We run scoped investigation engagements, during an active incident or after the dust settles, with senior US-based responders under NDA. An investigations practice, not a monitoring retainer.

01

What happened?

The forensic record: every system touched, every account used, every byte staged and moved.

02

How did they get in?

The entry vector, reproduced by our offensive team with their own hands. Demonstrated, not inferred.

03

Can it happen again?

Not through that door. We harden the weakness class, then re-attack the original path to prove it.

// when to call us

What we investigate

From live intrusions to quiet suspicions. If there's an attacker in the story, we can reconstruct their steps.

  • IR-01Active Compromise

    An attacker is in your environment right now. We help you scope, contain, and evict without tipping them off before you're ready.

  • IR-02Ransomware & Extortion

    Encryption events and data-theft extortion. We establish what was taken, how they got in, and whether they still have a way back inside.

  • IR-03BEC & Account Takeover

    Compromised mailboxes, fraudulent wires, and OAuth abuse. We trace the session history, the rules they planted, and everything they touched.

  • IR-04Web App & Cloud Breaches

    Exploited applications, leaked keys, and cloud tenant intrusions. These are the environments our offensive work lives in every day.

  • IR-05Insider Events

    Departing employees, data theft, and misuse of privileged access. Discreet investigation with evidence handling that holds up.

  • IR-06Compromise Assessment

    Something feels wrong but nothing has triggered. We hunt for evidence of compromise and either find the intrusion or give you real confidence.

$ ./how-it-works

From breach to proven root cause

A forensic investigation that ends the way our pentests do: with evidence, a fix path, and verification.

  1. 01

    Triage & Stabilize

    Evidence preserved

    A senior responder scopes the situation fast: what's affected, what evidence exists, what must be preserved, and what needs containment first.

  2. 02

    Collect Forensics

    Chain of custody

    Disk and memory acquisition, log collection, and cloud audit trails, gathered with chain-of-custody discipline so findings hold up later.

  3. 03

    Reconstruct the Timeline

    The attacker's story

    We piece the artifacts into the attacker's story: initial access, lateral movement, persistence, staging, and exfiltration, hour by hour.

  4. 04

    Prove the Root Cause

    Reproduced, not inferred

    This is where our offensive DNA matters. We reproduce the entry path ourselves, whether it was an exploit, a misconfiguration, or a stolen credential, so root cause is demonstrated rather than guessed.

  5. 05

    Fix & Verify

    Door provably closed

    You get an engineer-ready remediation sequence for the weakness class, then we re-attack the original path to confirm the door is actually closed.

// why platformsecurity

Most IR stops at containment. We don't.

Them

Contains the incident, closes the ticket, and moves on to the next client in the queue.

Us

Treats containment as the halfway point. The engagement isn't done until root cause is proven and the fix is verified.

Them

Reports end at patient zero: "initial access via phishing, probably."

Us

Reproduces the actual entry path with our own hands, so "how it happened" is a demonstrated fact.

Them

Analysts read artifacts against a playbook of known patterns.

Us

People who build exploit chains for a living read the same artifacts, and recognize tradecraft playbooks miss.

Them

Remediation arrives as a generic hardening checklist appended to the report.

Us

A prioritized, sequenced fix path for the weakness class, written for the engineers who will ship it.

Them

The fix is assumed to work because the alert stopped firing.

Us

We go back and re-attack the original entry vector. If it's still open, you hear it from us and not from them.

The best incident is the one that never lands. Before something goes wrong, or once the dust settles, pressure-test the same paths attackers use with red teaming and penetration testing.

$ cat deliverables.txt

What you get

  • 01A forensic timeline of attacker activity from initial access to last observed action, backed by evidence
  • 02Root-cause analysis of the entry vector, reproduced by our offensive team rather than inferred
  • 03Full scope of compromise (affected systems, accounts, and data) with an IOC set your team can hunt on
  • 04Containment and eradication guidance sequenced so you don't tip off an attacker who's still inside
  • 05A prioritized hardening roadmap that addresses the class of weakness, not just the instance
  • 06Executive summary and technical report written to hold up with your board, insurer, and counsel
  • 07Optional verification retest: we re-attack the original entry path to prove it's closed

// move fast, move smart

Breached? Get the full story.

Tell us what you're seeing, even if it's just a bad feeling. A senior responder reviews every message, active incidents go to the front of the queue, and an NDA is available before you share anything sensitive.