Digital forensic analysis & incident response
Maybe it’s obvious, files encrypted, a ransom note, accounts locked. Maybe it’s subtle, login alerts at 3am, an employee behaving strangely, a financial transaction you don’t recognize. Either way, the worst thing you can do right now is guess.
DFIR is the structured process of determining exactly what happened, what was accessed or exfiltrated, how the attacker got in, and what you need to do immediately to stop further damage. We approach every DFIR engagement the same way we approach penetration testing: attacker-mindset analysis, evidence-first methodology, and reporting clear enough for executives and detailed enough for your legal team.
Remote incident triage from $2,500 · NDA available on request · Evidence handled chain-of-custody ready
You’re here because something is wrong
Most organizations don’t discover they’ve been breached through their own detection tools. They hear it from a bank, a customer, a regulator, or a threat actor demanding payment. By then, logs may have rotated, attacker tooling may have been removed, and the window for clean evidence collection is narrowing fast.
Speed matters. But so does doing it correctly. Rushing to wipe and rebuild without a proper investigation means you may miss persistent backdoors, misidentify the entry point, or destroy evidence you’ll need for insurance claims, regulatory disclosure, or legal proceedings. That’s the problem DFIR solves: clarity under pressure, without sacrificing the integrity of the evidence.
What a DFIR investigation actually does
Our investigations are built around five areas that need to happen simultaneously, not sequentially.
Evidence preservation
Before anything else, we establish a preservation protocol. Rebooting a compromised host, clearing logs, or reimaging a device before acquisition permanently destroys forensic value. We guide your team on what not to touch and capture volatile memory, disk images, and log exports in a forensically sound, hash-verified manner.
Compromise scoping
We determine the actual blast radius. Is this contained to a single account, or has lateral movement spread across your environment? Are cloud identities compromised? Is there active persistence, a scheduled task, a C2 beacon still calling home? Scope defines the true extent of the incident, not just what’s visible on the surface.
Timeline reconstruction
We build a chronological record of attacker activity: when access was first obtained, which systems were touched, what data was staged or moved, and when the intrusion likely began, often weeks before detection. This timeline is the backbone of your incident report and essential for any compliance disclosure.
Containment guidance
Containment runs parallel to investigation, not after it. We provide prioritized steps, what to isolate, which credentials to rotate, which cloud tokens to invalidate, while analysis continues. Waiting until the investigation concludes to contain an active threat is a costly mistake.
Executive & technical reporting
You receive two outputs: a technical forensic package for your security team and a clear executive summary for leadership, legal, and your board if needed. Both are written with the understanding that this documentation may appear in front of regulators or in litigation.
Chain-of-custody documentation
Every piece of evidence is hashed, logged, and tracked from acquisition through analysis. If your case ends up in front of an insurer, regulator, or court, the custody trail holds up.
The incident types we investigate
Ransomware & extortion
File encryption, ransom note delivery, double-extortion (data exfiltration before encryption). We reconstruct the initial access vector, identify the ransomware strain, and assess what was exfiltrated before encryption occurred.
Credential compromise & account takeover
Unauthorized access via phishing, credential stuffing, or stolen session tokens. Common targets include Microsoft 365, Google Workspace, and AWS IAM. We trace the access path, map what was read or exported, and identify OAuth grants or forwarding rules left behind.
Insider activity
Unauthorized data access or exfiltration by employees, contractors, or terminated staff. We correlate access logs, data movement patterns, and endpoint artifacts to build a documented, defensible record.
Suspicious logins & anomalous access
Early-stage triage for organizations that aren’t certain they’ve been breached but have reason to believe something is wrong. We analyze available evidence and give you a direct answer.
Malware & spyware
Persistence mechanisms, C2 communication, credential harvesting, and lateral movement artifacts across Windows and macOS enterprise environments.
Cloud & SaaS data exposure
Misconfigured storage, exposed cloud identities, or third-party integrations that leaked data. We trace what was publicly reachable, for how long, and whether it was actually accessed.
How the investigation works, step by step
STEP 01
Confidential intake & scoping
We start with a scoping call to understand what’s been observed, which systems and accounts are in scope, and what the investigation needs to produce, whether that’s operational containment, legal documentation, or regulatory disclosure support.
STEP 02
Evidence preservation
We guide your team through immediate preservation steps and, where required, perform remote forensic acquisition of disk images, memory captures, and log exports.
STEP 03
Analysis & timeline construction
We work through endpoint artifacts, identity logs, cloud telemetry, and network data to build the attack timeline and map attacker activity across your environment.
STEP 04
Containment & eradication
Prioritized containment steps are delivered in parallel with the investigation. You’re not waiting until the end of a multi-week analysis to start reducing your exposure.
STEP 05
Reporting & debrief
A complete forensic evidence package and executive summary are delivered. We walk your team through findings and answer questions from legal, compliance, or leadership directly.
What you receive at the end
- Written attack timeline, referenced to forensic evidence
- Forensic evidence package with hash verification records
- Compromise scope assessment covering affected systems, accounts, and data
- Indicators of compromise (IOCs) where identified
- Prioritized containment and eradication recommendations
- Executive summary suitable for board, legal, or regulatory reporting
- Optional: formal evidence handling documentation for insurance or litigation support
DFIR as part of a mature security program
DFIR doesn’t exist in isolation. Organizations that respond most effectively to incidents are the ones that have already done the foundational work, penetration testing, compliance readiness, and security hardening. If you’ve worked with us on a web application penetration test or compliance risk assessment, our DFIR team already understands how to apply attacker-mindset thinking to your environment. The transition from proactive testing to reactive investigation is seamless.
Post-investigation, we help you understand how the breach occurred within your broader security posture, and whether a formal penetration test, a compliance gap assessment, or targeted hardening should be the next step.
Why organizations trust Pentest Testing Corp for DFIR
Pentest Testing Corp has delivered security engagements to more than 257 organizations across 30+ countries, with over 6,000 validated vulnerabilities identified across web, API, mobile, cloud, and network environments. Our CEO, Md. Shofiur, holds certifications in Digital Forensics, Windows Security & Forensics, Ethical Hacking, and ISO/IEC 27001, and is a top-rated cybersecurity professional on Freelancer.com.
That background matters in DFIR. Forensic analysis without attacker-mindset thinking misses persistence mechanisms, misidentifies entry points, and underestimates scope. We conduct investigations the same way we conduct penetration tests, by thinking like the attacker who was already inside.
| Tier | Starting from | What’s included |
|---|---|---|
| Rapid triage (remote) | $2,500 | Intake, initial log review, triage analysis, containment guidance, findings summary |
| Investigation & containment | $6,500 | Everything in triage plus deeper forensic analysis, account/device investigation, recovery roadmap, hardening guidance |
| Full DFIR engagement | $12,000+ | Custom scope, full investigation plan, evidence collection, root cause analysis, stakeholder reporting, optional monitoring |
Complex incidents involving multiple devices, accounts, or jurisdictions are scoped individually after intake.
Frequently asked questions
What’s the difference between DFIR and a penetration test?
A penetration test is proactive, we simulate an attack to find vulnerabilities before a real attacker does. DFIR is reactive, we investigate an incident that has already occurred to determine what happened, how it happened, and what the full impact was. Both are essential parts of a mature security program, and they’re most effective when the same team handles both.
Can you investigate a ransomware incident remotely?
Yes. Most triage and investigative work can be conducted remotely. For situations requiring forensic disk imaging or physical evidence handling, we coordinate on-site acquisition or walk your team through a secure remote collection process.
What if we’ve already started cleaning up the affected systems?
Start the investigation as soon as possible, even if some evidence has been lost. We work with whatever artifacts remain and are transparent about the limitations of the findings. A structured investigation with documented scope is still far more defensible than no investigation at all, and partial evidence often yields more than expected.
Do I need a DFIR report for cyber insurance or regulatory disclosure?
In most cases, yes. Cyber insurers increasingly require documented evidence of investigation before covering breach-related costs. Regulators under GDPR, HIPAA, and PCI DSS may require you to demonstrate what data was affected and what remediation steps were taken. Our reports are written with exactly these audiences in mind.
Can you investigate hacked iPhones and Android phones?
Yes, within OS security and available logs and backups. We still provide high-confidence conclusions using account telemetry and correlating evidence even when deep extraction is limited by mobile OS security restrictions.
Can you investigate email or cloud account compromise?
Yes. We analyze logs, access events, and recovery paths for Google Workspace, Microsoft 365, Apple ID, and cloud platform accounts including AWS, Azure, and GCP.
Dealing with an active incident? Call or message us now.
We’ll scope the situation, advise on immediate preservation steps, and provide a clear investigation plan, fast.
NDA available on request · Chain-of-custody evidence handling · Insurance and regulatory-ready reporting