Incident Response

Containment, forensics and recovery support when something has already happened, available ad hoc or on a pre-agreed retainer.

How it plays out

CRITICAL

How this gets attacked, and what holds

The route a real attacker takes through this surface, in the order they take it. Nothing here is theoretical: these are the findings that recur across engagements.

  1. 01

    Detection

    An intruder operating for weeks because the only signal was a line in a log nobody reads.

  2. 02

    Containment

    Rebooting the affected machine, which destroys memory resident evidence and tells the intruder they have been noticed.

  3. 03

    Credentials

    One stolen password reused across systems, and tokens that stay valid long after the password is finally reset.

  4. 04

    Persistence

    The way back in that survives the cleanup: a scheduled task, an added SSH key, an OAuth application granted by a compromised account.

  5. 05

    Evidence

    Logs rotate away mid investigation and the timeline can no longer be reconstructed.

Why teams choose us

Two working days

From enquiry to a fixed written quote. No discovery-call funnel.

Fixed price

Quoted before work starts. No hourly creep, no surprise invoice.

Retest included

We verify your fixes and reissue the report at no extra cost.

Authorised only

Written authorisation and rules of engagement before anything is touched.

Scope this engagement

Tell us the target and the deadline. We reply with a fixed quote within two working days.

Target, rough size and any deadline. Do not include credentials.

We use your details only to reply to this enquiry. See the privacy policy.