Cyber Swiss
Army Knife Squad

Services / Microsoft 365 and endpoint security

Incident response and digital forensics

Tenant compromise, phishing, malware, IAM abuse, cloud billing abuse. Containment first, then evidence and root cause, then the changes that stop it happening again. Available at short notice, because that is when it is needed.

What usually gets in the way

  • Attacker access still live while the investigation is being scoped.
  • Unclear what was reached, changed or taken.
  • Logs missing, too short a retention, or never enabled.
  • Business pressure to restore service before the cause is understood.
  • Reporting obligations to customers, insurers or regulators.
  • No confidence the same route will not be used again.

How we approach it

  • Contain first: revoke sessions, reset credentials, close the route in.
  • Preserve evidence before anything is rebuilt.
  • Reconstruct the timeline from available telemetry.
  • Identify the initial access and every persistence mechanism.
  • Support customer, insurer and regulatory reporting with facts.
  • Deliver the hardening that closes the gap permanently.

What you end up with

  • Attacker access removed and verified as removed.
  • A documented timeline of what happened and what was reached.
  • Evidence retained for insurers, customers or regulators.
  • Specific changes made so the same route no longer works.

Start with a conversation

Tell us where you are with incident response and digital forensics and we’ll tell you what it actually takes.