Incident Response
Containment, forensics and recovery support when something has already happened, available ad hoc or on a pre-agreed retainer.
How it plays out
How this gets attacked, and what holds
The route a real attacker takes through this surface, in the order they take it. Nothing here is theoretical: these are the findings that recur across engagements.
- 01
Detection
An intruder operating for weeks because the only signal was a line in a log nobody reads.
- 02
Containment
Rebooting the affected machine, which destroys memory resident evidence and tells the intruder they have been noticed.
- 03
Credentials
One stolen password reused across systems, and tokens that stay valid long after the password is finally reset.
- 04
Persistence
The way back in that survives the cleanup: a scheduled task, an added SSH key, an OAuth application granted by a compromised account.
- 05
Evidence
Logs rotate away mid investigation and the timeline can no longer be reconstructed.
Why teams choose us
Two working days
From enquiry to a fixed written quote. No discovery-call funnel.
Fixed price
Quoted before work starts. No hourly creep, no surprise invoice.
Retest included
We verify your fixes and reissue the report at no extra cost.
Authorised only
Written authorisation and rules of engagement before anything is touched.
Scope this engagement
Tell us the target and the deadline. We reply with a fixed quote within two working days.