Digital Forensics Service
The SecureSys digital forensics and compromise assessment service establishes the technical root cause of security incidents, builds the attack timeline and reveals the real scope of the incident.
What Is Digital Forensics?
Digital forensics is specialist work carried out to examine security incidents, data breaches, unauthorised access, malicious software activity and other suspicious operations on digital systems, to preserve the evidence and to establish how the incident took place.
The core purpose of digital forensics work is not simply to confirm that a security incident occurred. The real objective is to establish, through technical findings:
when the incident began, how the attacker accessed the system, which systems they moved through, which user accounts were affected, which data was accessed or taken out, and how far the attack progressed within the organisation
The digital forensics service provided by SecureSys helps organisations analyse cyber security incidents in technical terms, define the scope of the incident and build the security actions that will prevent similar attacks in future.
Digital forensics work is critical in particular following:
ransomware attacks, data breaches, unauthorised access, malware infections, account takeover incidents, insider threats and suspicious user activity
Why Does Digital Forensics Matter?
The problem organisations most frequently face after a cyber security incident is not knowing the real scope of the incident.
Malicious software may have been detected on a user's computer, for example.
The questions that need answering, however, are these:
Is the malware present only on this computer?
Has it spread to other systems?
Have user credentials been compromised?
Did the attacker reach the Active Directory environment?
Was any data taken out?
How long did the attacker remain inside the organisation?
Is the incident still ongoing?
Response work carried out without accurate answers to these questions can remain incomplete.
Simply reformatting the infected computer, for example, may not remove the persistence mechanisms the attacker left on other systems.
Professional digital forensics work therefore has to focus not only on the visible part of the incident but on the full attack chain.
The SecureSys Digital Forensics Service
SecureSys provides professional digital forensics, incident investigation and compromise assessment services for analysing security incidents occurring on organisations' digital systems.
Depending on the type of incident, the scope can consist of technical activities such as:
disk analysis, memory forensics, endpoint analysis, log review, malware analysis, user activity analysis, network artefact analysis, email examination and attack timeline construction
The aim is not solely to gather technical evidence.
The real objective is to explain the incident in terms that mean something to the organisation.
What Is a Compromise Assessment?
A compromise assessment is the systematic investigation of unauthorised access, malware infection or attacker activity that may have taken place previously, or may still be ongoing, on an organisation's systems.
This work differs from a conventional penetration test.
A penetration test seeks the answer to this question:
"Can an attacker get into the systems?"
A compromise assessment seeks the answer to this one:
"Might an attacker already be inside our systems?"
A compromise assessment is therefore particularly valuable after a suspicious security incident, or where the organisation is not confident about its current security posture.
When Should a Compromise Assessment Be Carried Out?
A compromise assessment is not carried out only after a major attack.
The work can be considered in the following situations:
- Suspicious network traffic detected
- A critical alert raised on EDR or SIEM
- Unusual sign-in activity seen on a user account
- Malicious software detected
- A ransomware attack experienced
- Suspicion of a data leak
- Information belonging to the organisation seen on the dark web
- Suspicion that administrator or critical user accounts have been compromised
- A wish to verify the security posture of newly acquired or merged company infrastructure
- Assessment of systems that have not had a security review for a long period
A compromise assessment can also be carried out proactively.
Even where the organisation has seen no sign of an attack, it may want to check whether there are historical traces of one.
How Is a Compromise Assessment Carried Out?
Compromise assessment work can be carried out using different methods depending on the organisation's existing infrastructure and the scope of the incident.
1. Defining the scope
The systems to be examined are established first.
These can include:
endpoint devices, servers, Active Directory, SIEM logs, EDR/XDR systems, firewall records, VPN logs and critical applications
2. IOC scanning
Known malicious indicators can be searched for across the systems.
These can include:
malicious IP addresses, domains, file hashes, process names, registry entries and other indicator of compromise (IOC) values
3. Behavioural analysis
Looking only at known IOCs is not sufficient.
Attackers can use new or unknown techniques.
Suspicious behaviour such as the following therefore has to be analysed:
unusual process execution, PowerShell activity, credential access behaviour, lateral movement, persistence and privilege escalation
4. Endpoint analysis
Disk, memory or endpoint telemetry data obtained from critical systems can be examined.
5. Active Directory analysis
Suspicious accounts, privileged user activity and unusual authentication records can be assessed.
6. Network and log analysis
Firewall, proxy, DNS, VPN, SIEM and other log sources are examined in order to reveal the attacker's movement between systems.
7. Timeline construction
The events identified are placed in chronological order so that the progression of the attack can be established.
The Difference Between Compromise Assessment and Incident Response
Compromise assessment and incident response are close but have different objectives.
Compromise assessment focuses on establishing whether an attacker is present on the systems.
Incident response aims to respond to a confirmed security incident, remove the attacker from the system and return operations to a secure state.
The process can therefore often run as follows:
suspicion → compromise assessment → confirmation of the attack → incident response → digital forensics → recovery → lessons learned
This allows the organisation not only to stop the attack but also to understand its root cause.
How Does the Digital Forensics Process Work?
1. Initial assessment of the incident
The information available about the type of incident and the systems it affected is gathered first.
The initial assessment establishes when the incident was noticed, which security products raised alerts and which systems may have been affected.
2. Preservation of digital evidence
One of the most important principles in digital forensics is preserving the integrity of the evidence.
Incorrect intervention can cause important evidence to be lost.
Operations on critical systems therefore have to be planned in a controlled way.
3. Data collection
Disk images, memory dumps, log files and other digital artefacts can be collected.
4. Technical analysis
The data collected is analysed for attacker activity.
5. Attack timeline
The order in which events took place is established.
6. Impact analysis
Which systems and which data were affected is assessed.
7. Reporting
The technical findings and the recommended actions are reported.
What Is Disk Forensics?
Disk forensics is the examination of the digital artefacts held on computer or server disks.
This analysis can identify deleted files, user activity, application records, file access and traces of malicious software.
Disk analysis is particularly valuable in examining incidents that took place in the past.
Even where the attacker has left the system, traces of some activity can remain on disk.
What Is Memory Forensics?
Memory forensics is the analysis of a running system's RAM.
Memory analysis matters in particular for examining fileless malware and running processes.
Where the attacker used malicious code running only in memory, sufficient traces may not exist on disk.
Memory dump analysis can therefore provide important information such as:
processes, network connections, credential artefacts and injected code
Malware Forensics and Malicious Software Analysis
Where malicious software is detected in a security incident, understanding how the malware works is important.
Malware analysis can examine:
file behaviour, network connections, persistence mechanisms, command and control infrastructure and the artefacts created
This information is used not only to understand the malware but also to check whether the same malware is present on the organisation's other systems.
Digital Forensics in Ransomware Incidents
Ransomware attacks are among the most critical security incidents for organisations.
In a ransomware incident, focusing solely on recovering the encrypted files is not sufficient.
How the attacker entered the system has to be understood first.
The attacker may have gained initial access through a VPN account, a phishing email, a vulnerability or stolen user credentials.
They may then have moved within the organisation's network for days or weeks.
Ransomware forensics work therefore has to assess all of the following stages:
initial access, credential access, privilege escalation, lateral movement, data exfiltration and encryption
Data Exfiltration Analysis in a Ransomware Attack
Taking data out of the organisation before encrypting the files is a common technique in modern ransomware attacks.
After the incident, therefore, the answer has to be sought not only to "which files were encrypted?" but also to:
"which data may have been taken out?"
Firewall, proxy, endpoint and network logs can provide important information on this.
Active Directory Forensics
Active Directory is one of the critical targets in many corporate attacks.
Attackers try to control a large part of the organisation's infrastructure by reaching highly privileged accounts.
Active Directory forensic examination can look at:
failed and successful sign-ins, new account creation, group membership changes, privileged account activity and unusual authentication behaviour
Changes in Domain Admin and other highly privileged groups in particular have to be assessed carefully.
Windows Event Log Analysis
Many security events occurring on Windows systems leave traces in the Event Log.
These logs can contain important information about sign-ins, process creation, service changes and user activity.
Digital forensics specialists can bring different Event IDs together in order to build the attack timeline.
The absence of logs does not mean there was no attack, however.
Logs having been deleted can itself be an indicator of attacker activity.
Linux Forensics
Forensic examination on Linux servers can be carried out through:
authentication logs, shell history, process records, cron jobs, SSH access and file changes
Linux forensics is particularly important on web servers and critical backend systems.
Activity such as the attacker creating a new user, adding an SSH key or establishing persistence through cron can be investigated.
What Is Network Forensics?
Network forensics examines the attacker's movement across the network.
Firewall, IDS/IPS, NDR, proxy, DNS and packet capture data can be analysed.
This can identify:
command and control connections, lateral movement, data leakage and suspicious external connections
Network forensics matters in particular for understanding how the attacker moved from one system to another.
Email Forensic Analysis
Email systems hold critical evidence in phishing and business email compromise attacks.
Email forensic examination can assess:
mail headers, the sending infrastructure, SPF/DKIM/DMARC results, malicious links, attachments and user interaction
This makes it possible to understand which source the phishing email came from and what effect it had on the user.
Cloud Forensics
As organisations have come to make heavy use of cloud platforms, cloud forensics has gained importance.
On AWS, Azure and other cloud platforms, the following can be used in incident analysis:
authentication logs, IAM changes, API activity, storage access and network logs
Cloud audit logs are a critical source of evidence, particularly in attacks carried out with compromised cloud credentials.
Microsoft 365 and Entra ID Incident Analysis
Account takeover is one of the common security risks in organisations using Microsoft 365 and Entra ID.
Forensic analysis can assess:
suspicious login records, country and IP changes, MFA activity, mailbox forwarding rules, OAuth permissions and user sessions
The attacker may have created an automatic forwarding rule on the mailbox they compromised, for example.
Configuration of that kind can allow the attacker to continue gathering information over a long period.
Business Email Compromise Forensics
In BEC attacks, the attacker impersonates a company executive or a supplier in order to have a financial transaction carried out.
In some cases the attacker compromises the real email account and follows the existing correspondence.
They then change the payment details at the right moment.
Forensic analysis can reveal how the attack was carried out by examining:
mailbox login records, forwarding rules, sent emails and authentication logs
Insider Threat Forensic Analysis
Not every security incident originates with an external attacker.
Suspicious activity by employees or authorised users can also create serious risk for the organisation.
Insider threat analysis can examine:
file access, USB usage, email traffic, cloud storage activity and critical data transfers
Work of this kind has to be carried out in a controlled way, taking legal and personal data requirements into account.
Data Breach Analysis
Where there is suspicion that data has left the organisation, the scope of the incident has to be established.
The core questions are these:
Which data was affected?
How many records may have been accessed?
Was the data genuinely taken out?
Through which user or system did it happen?
These questions matter in particular on systems processing personal data or critical corporate information.
Root Cause Analysis
One of the most critical outputs of digital forensics work is root cause analysis.
Not only the consequences of the attack but also its starting point has to be established.
The root cause of a ransomware attack may be a weak VPN password, an out-of-date security appliance or a phishing attack, for example.
If the root cause is not corrected, the possibility of a similar attack recurring remains even after the systems have been cleaned.
Timeline Analysis
Showing the incident chronologically is extremely valuable in a professional digital forensics report.
An attack may have developed as follows, for example:
3 March 02:14 – suspicious VPN login
3 March 02:21 – access to the first server
3 March 03:05 – credential dumping
3 March 04:10 – lateral movement
4 March 01:30 – data exfiltration
5 March 04:45 – ransomware execution
This timeline makes the real structure of the attack easier to understand.
Persistence Analysis
Once attackers have reached the systems, they create persistence mechanisms so as not to lose their access.
These can include methods such as:
a new user account, a scheduled task, a service, a registry change, a startup script and a web shell
Investigating these persistence mechanisms is critical in compromise assessment and digital forensics work.
Lateral Movement Analysis
The first system the attacker compromises is often not the final target.
The attacker moves towards other systems within the organisation's network.
This behaviour is defined as lateral movement.
Forensic analysis can establish which user accounts the attacker used, which systems they reached and which protocols they used.
This information makes it possible to reveal the real scope of the attack.
Credential Access Analysis
User credentials are one of the most important resources allowing attackers to progress within an organisation.
Forensic analysis can investigate activity related to:
credential dumping, password hashes, cached credentials, tokens and service accounts
This information helps establish which accounts the attacker may have compromised.
Data Exfiltration Analysis
Establishing whether an attacker took data out of the organisation is one of the most difficult areas of digital forensics.
Network logs, proxy records, cloud activity and endpoint data can be assessed together for this analysis.
Large data transfers, connections to unknown cloud services or suspicious compressed files can all indicate a data leak.
IOC and IOA Analysis
Digital forensics work can assess both indicator of compromise (IOC) and indicator of attack (IOA) signals.
An IOC shows the technical traces an attack left behind.
An IOA describes attacker behaviour.
A particular malware hash is an IOC, for example, whereas credential dumping behaviour through PowerShell is assessed as an IOA.
Behaviour-based analysis matters in particular in modern compromise assessment work.
Mapping the Incident to MITRE ATT&CK
The attacker activity identified through forensic analysis can be related to MITRE ATT&CK techniques.
The attack chain can be mapped to stages such as:
initial access → execution → persistence → credential access → discovery → lateral movement → exfiltration
This allows the organisation to see which techniques the attacker succeeded with.
The same information can then be used in purple team or detection engineering work.
Digital Forensics and SOC Integration
Digital forensics should not be used solely to investigate the past.
The information obtained provides important input for improving SOC processes.
Where a new technique used by the attacker is identified, a new correlation rule can be created on the SIEM.
A new detection rule can be defined on the EDR.
Malicious infrastructure can be blocked at the firewall or DNS layer.
An incident that has already happened then becomes a learning process that strengthens the organisation's future defence.
The Lessons Learned Process
Preparing a technical report is not sufficient at the end of incident response and digital forensics work.
What the organisation learned from the incident has to be assessed.
The lessons learned process can establish which security control failed, why the attack was detected late, which processes need improving and which new controls need to be introduced.
This approach raises the organisation's cyber security maturity.
What Does a Digital Forensics Report Contain?
Depending on the scope of the project, a professional digital forensics report can include:
a summary of the incident, the systems affected, the attack timeline, the IOC/IOA indicators identified, attacker activity, the user accounts affected, a data leakage assessment, the root cause and improvement recommendations
Alongside the technical detail, an executive summary allowing management to understand the business impact of the incident can also be prepared.
Evidence Integrity in Digital Forensics
Preserving the integrity of the digital evidence obtained is important in digital forensics work.
Data integrity can be verified using hash values on disk images and other evidence.
Who collected the evidence, when and by what method also has to be recorded.
This matters in particular for incidents that may be used in legal proceedings.
What Is Chain of Custody?
Chain of custody is the recording of who accessed digital evidence, and what operations were carried out on it, from the moment it was collected until the analysis is complete.
That record is important for demonstrating that the evidence has not changed and has been handled in a controlled way.
Chain of custody procedures have to be taken into account in particular for incidents that may turn into legal or disciplinary proceedings.
Which Organisations Need Digital Forensics?
Digital forensics services are important in particular for:
financial institutions, public sector bodies, the defence industry, energy companies, healthcare organisations, e-commerce businesses, technology companies, holding groups and critical infrastructure operators
Any organisation processing data and using digital systems may nonetheless need digital forensics if it experiences a security incident.
Proactive Compromise Assessment
A compromise assessment does not have to be carried out only after an incident.
Organisations can have their systems checked periodically for traces of past attacks.
This is valuable in particular in environments that have not had a security assessment for a long period.
The aim is to be able to answer the following with technical data:
"We have had no alerts yet, but how confident are we that there is no attacker inside?"
The Relationship Between Digital Forensics and Incident Response
Incident response covers responding to a cyber security incident; digital forensics covers examining it in technical terms. The two disciplines work together in most cyber incidents.
When an attack is detected, its spread has to be stopped first, critical systems protected and attacker access restricted. Digital forensics techniques are then used to investigate how the attack began, which systems it affected and which user accounts were used.
Modern cyber incident response processes are therefore mostly handled through the DFIR – digital forensics and incident response approach.
The core objective of the SecureSys DFIR approach is not simply to get the system running again. The aim is to understand the root cause of the incident, reveal the traces the attacker left on the system and define the security controls needed to prevent a similar incident recurring.
What Is DFIR?
DFIR – digital forensics and incident response is the security approach in which digital forensics and cyber incident response processes are run together.
DFIR work can consist of the following stages:
incident detection, containment, digital evidence collection, analysis, identification of attacker activity, eradication, recovery and post-incident improvement
The DFIR approach is critical in particular in ransomware, data breach and advanced targeted attacks.
An organisation that has simply deleted the malware may not have ended the attack.
The attacker may have created different user accounts, added new services or left persistence mechanisms behind.
DFIR work therefore addresses the entire lifecycle of the attack.
What Is a Breach Investigation?
A breach investigation is the detailed technical investigation of a data breach that has taken place, or is suspected of having taken place.
One of the core objectives of this work is to define the scope of the incident.
The answers to questions such as the following are investigated:
which systems were compromised, which users were affected, which files were accessed, how long the attacker remained on the system and whether data was taken out
Breach investigation is important in particular in environments processing personal data, financial information, trade secrets or critical corporate documents.
In the data breach analyses SecureSys carries out, the available log records, endpoint data, network data and digital artefacts can be assessed together.
Account Compromise Investigation
Where a user account is suspected of having been compromised, changing the password alone may not be sufficient.
After reaching the account, the attacker may have created new sessions, added a forwarding rule or reached other systems.
Account compromise investigation covers the detailed examination of compromised or suspicious user accounts.
This can analyse:
successful and failed login records, MFA activity, device information, IP addresses, session records, password changes and authorisation changes
Analysis of this kind is important in particular for Microsoft 365, Entra ID, VPN and Active Directory accounts.
Microsoft 365 Compromise Assessment
Account takeover, phishing and business email compromise are among the common security risks in Microsoft 365 environments.
A Microsoft 365 compromise assessment can examine suspicious user sessions, new device sign-ins, inbox rule changes, mailbox forwarding, OAuth application permissions and administrator activity.
After reaching a user account, for example, the attacker may have created a rule automatically forwarding emails to an external address.
Even if the user's password is changed, that forwarding rule can remain active.
Changing the password alone is therefore not a sufficient response in Microsoft 365 incidents.
Active Directory Compromise Assessment
An Active Directory compromise assessment investigates past or ongoing attacker activity in the organisation's Active Directory infrastructure.
One of the attackers' objectives is to reach highly privileged accounts.
The analysis can therefore assess:
Domain Admin activity, new user and group creation, service accounts, unusual authentication, Kerberos activity and traces of privilege escalation
An attacker obtaining high privilege in an Active Directory environment can mean critical risk for the whole organisation.
The AD environment is therefore one of the important areas of analysis in compromise assessment work.
Endpoint Compromise Assessment
Endpoint devices can be the systems through which attackers gain initial access or move within the organisation.
An endpoint compromise assessment assesses user computers and servers for traces of attack.
The analysis can examine:
suspicious processes, persistence mechanisms, scheduled tasks, services, registry changes, malware artefacts and traces of command execution
The aim is not only to find known malware but also to identify attacker behaviour.
IOC Hunting
IOC hunting is the search for known attack indicators across the organisation's systems.
IOC lists can consist of IP addresses, domains, URLs, file hashes and other malware indicators.
New IOCs used in an attack campaign targeting the organisation's sector may have been identified, for example.
These indicators can be searched for in the organisation's EDR, SIEM, firewall, proxy and DNS logs.
This makes it possible to assess whether the organisation has previously had contact with the threat actor concerned.
The Difference Between Threat Hunting and Compromise Assessment
Threat hunting and compromise assessment are close concepts.
Compromise assessment systematically investigates whether past or ongoing attacker activity exists on the systems.
Threat hunting focuses on proactively searching the organisation's systems for known or hypothesised attacker behaviour.
Searching the logs for particular behaviour on the hypothesis that "the attacker may have carried out credential dumping through PowerShell" is a threat hunting exercise, for example.
Used together, these two approaches make it possible to detect attackers not only through known IOCs but also through behavioural techniques.
Fileless Malware Analysis
Some modern attacks are carried out without leaving a conventional malicious file on disk.
This approach is generally associated with fileless malware or living-off-the-land techniques.
The attacker can operate using PowerShell, WMI, rundll32, mshta or tools already present on the system.
These attacks are not always easily detected by conventional antivirus systems.
Memory forensics, EDR telemetry and Windows Event Log analysis play an important role in examining fileless attacks.
Living off the Land Attacks
Living off the land is the abuse of legitimate tools present in the operating system by attackers, rather than installing malicious software.
PowerShell, Windows Management Instrumentation and other system tools can be used for attack purposes.
This can cause attacker activity to be confused with normal administrative operations.
Digital forensics and compromise assessment work therefore has to assess not only unknown files but also unusual use of legitimate tools.
Web Shell Forensics
Web servers are important targets for attackers.
An attacker exploiting a vulnerability in a web application can leave a web shell on the server.
The web shell then allows the attacker to run commands remotely on the system.
Digital forensics work can examine changes to web files, newly created files, web server access logs and suspicious process activity.
Where a web shell is detected, deleting the file alone is not sufficient.
Which vulnerability the attacker used to obtain that access also has to be established.
Persistence Hunting
Investigating the persistence mechanisms the attacker left in order to regain access to the organisation's systems can be treated as persistence hunting.
The attacker can create a new user account, a startup entry, a scheduled task, a service, a registry key or other authentication mechanisms.
Persistence hunting is important in particular after incident response, in order to confirm that attacker access has been removed entirely.
Command and Control Analysis
Attackers use command and control (C2) infrastructure in order to control the systems they have compromised remotely.
Digital forensics and network forensics work can analyse suspicious external connections, DNS queries, beaconing behaviour and known malicious infrastructure.
Connections made at regular intervals to the same external IP or domain can indicate the attacker's C2 communication.
Beaconing Analysis
Some malware and attack tools make small network connections to the attacker's infrastructure at regular intervals.
This behaviour is called beaconing.
An infected system may be sending a connection to a particular domain every 60 seconds, for example.
Time-based analysis of network logs can identify periodic connections of this kind.
Lateral Movement Hunting
An attacker reaching the organisation's network often does not remain on a single system.
They can use RDP, SMB, WinRM, PsExec or other administrative protocols in order to move to other systems.
Lateral movement hunting investigates that movement through log and endpoint data.
The same account connecting to a large number of systems within a short period, or an administrative protocol not normally used becoming active, can indicate suspicious activity.
Privileged Account Investigation
Compromising highly privileged accounts is one of the critical stages in corporate attacks.
The activity of Domain Admin, Global Administrator, root and other privileged accounts therefore has to be examined in detail.
Forensic analysis can assess which systems logins were carried out from, which privilege changes were made and whether the account deviated from its normal usage pattern.
OAuth Abuse Analysis
In modern cloud attacks, attackers do not always have to continue using the user's password.
Persistent access can be obtained through permissions granted to malicious OAuth applications.
The user may have granted an application mailbox read permission on a phishing page, for example.
Even if the password is changed, the OAuth token can remain active.
Examining OAuth permissions is therefore important in Microsoft 365 and cloud forensics work.
MFA Bypass and Session Hijacking Analysis
MFA significantly improves account security, but attackers can in some cases compromise user sessions and try to use the sessions established after MFA.
Account takeover investigations therefore have to look not only at password use but also at:
session tokens, cookies, OAuth tokens and unusual device activity
This matters for detecting modern identity-based attacks.
Cloud Compromise Assessment
As organisations have migrated to AWS, Azure and other cloud platforms, traces of attack have come to be held on different systems.
A cloud compromise assessment investigates suspicious activity in cloud environments.
This can examine IAM changes, new access key creation, public storage access, API calls, new user creation and unusual resource activity.
Preserving cloud audit logs is critical for forensic examination.
Kubernetes and Container Forensics
As container-based systems have become widespread, Kubernetes forensics and container incident analysis have also become important.
An attacker may have run commands inside a container, created a new pod or reached cluster credentials.
The analysis can examine Kubernetes audit logs, container activity, image changes, service account usage and cluster access.
This area is important in particular for cloud-native applications.
Why Does Timeline Reconstruction Matter?
Individual security findings may not be sufficient to understand the attack as a whole.
Logs and artefacts obtained from different systems therefore have to be brought together on the same timeline.
An attack chain such as the following can emerge, for example:
01:15 VPN login → 01:20 PowerShell execution → 01:35 credential access → 02:10 RDP connection → 03:00 data archive → 03:25 outbound transfer
This structure shows the attacker's movement within the organisation clearly.
Why Does Log Retention Matter for Digital Forensics?
Some cyber incidents are noticed weeks or months after the attack began.
If logs are kept for only a few days, establishing the starting point of the attack may not be possible.
It is therefore important that organisations establish appropriate retention policies for their SIEM, firewall, VPN, Active Directory, endpoint, cloud and application logs.
Digital forensics capability depends not only on the analysis tools used but also on the availability of historical data.
What Is Forensic Readiness?
Forensic readiness is preparing the organisation for forensic examination before a possible cyber security incident occurs.
This approach establishes the log sources needed, plans log retention periods, provides time synchronisation and enables the necessary audit records on critical systems.
Security teams can then reach sufficient evidence when a real incident occurs.
Alongside the digital forensics work SecureSys carries out, recommendations for developing a forensic readiness approach can also be provided.
Digital Forensics and NDR
Network detection and response systems can be an important data source for identifying attacker behaviour across the network.
During digital forensics work, NDR records can be analysed for lateral movement, command and control connections, use of unknown protocols and data transfers.
Assessing endpoint and network data together allows the attack to be understood more completely.
Digital Forensics and EDR/XDR
EDR and XDR platforms provide important telemetry about the process, network and user activity occurring on endpoints.
This data can be examined retrospectively during a compromise assessment.
Which process started a suspicious PowerShell command, which user it ran under and which external IP address it connected to can be established, for example.
EDR/XDR data is therefore one of the most valuable data sources in modern digital forensics work.
Digital Forensics and SIEM
Because SIEM systems hold logs from different security sources centrally, they play an important role in incident examination.
Digital forensics specialists can build the attack timeline by correlating authentication, firewall, VPN, proxy, Active Directory and application logs through the SIEM.
The presence of sufficient logs on the SIEM can significantly affect both the duration and the accuracy of a compromise assessment.
What Does a Compromise Assessment Produce?
At the end of a compromise assessment, assessing the organisation simply as "clean" or "infected" is not sufficient.
The work should aim to answer the following questions as far as possible:
Is there any trace of an active attacker?
Were indicators of past attack found?
Which systems may have been affected?
Which user accounts' credentials are at risk?
Is there a persistence mechanism in place?
Has lateral movement taken place?
Were external connections or C2 communication detected?
Is there any indicator of data leakage?
Which security controls need improving?
The answers to these questions provide the basis for building the organisation's incident response plan.
The Clean-Up Process After a Compromise Assessment
Where attacker activity is detected, cleaning systems at random can alert the attacker or cause important evidence to be lost.
The eradication process therefore has to be planned in a controlled way.
Where necessary, the following should be carried out to a plan:
removal of malicious files, cleaning of persistence mechanisms, changing user credentials, resetting privileged accounts, terminating sessions and blocking network access
Carrying these out in a coordinated way in critical incidents helps prevent the attacker using another route back in.
Post-Incident Hardening
Once the digital forensics work is complete, the security problems that allowed the attack have to be corrected.
This stage can be treated as post-incident hardening.
The incident may have identified a lack of MFA, weak network segmentation, insufficient logging, an out-of-date system or an over-privileged user account, for example.
Turning these findings into a security improvement plan makes it harder for the same attack chain to be used again.
Purple Team After Digital Forensics
Information obtained from real attacks provides an extremely valuable test scenario for the organisation.
The techniques the attacker used can be mapped to MITRE ATT&CK following the forensic work.
The red team can then reapply the same attack techniques in a controlled way.
The blue team checks whether the newly created detection mechanisms identify the attack.
A real incident can therefore be turned into the cycle:
digital forensics → MITRE ATT&CK → detection engineering → purple team → validation
The SecureSys Compromise Assessment Approach
In SecureSys compromise assessment work, the objective is not simply to run known IOC lists against the systems.
Because modern attacks frequently use new infrastructure, legitimate system tools and identity-based techniques, behavioural analysis matters as well.
The scope can therefore assess the following together:
IOC hunting, IOA analysis, endpoint forensics, Active Directory examination, Microsoft 365 analysis, network forensics, SIEM log analysis, persistence hunting and lateral movement analysis
The SecureSys compromise assessment service is a professional cyber security investigation service for identifying past or ongoing attacker activity, traces of malware, signs of account takeover, lateral movement, persistence and indicators of data leakage on an organisation's systems.
Why the SecureSys Digital Forensics Service?
Digital forensics work requires high technical expertise and systematic analysis.
Incorrect intervention during an incident can cause important evidence to be lost or attacker activity to be misinterpreted.
The SecureSys digital forensics service establishes the technical root cause of security incidents, builds the attack timeline and reveals the real scope of the incident.
Depending on the scope, the following work can be carried out:
compromise assessment, endpoint forensics, memory forensics, network forensics, Active Directory examination, malware analysis, cloud forensics and data breach analysis
The aim is that the findings do not merely become an incident report but also contribute to developing the SOC and the security infrastructure.
SecureSys is a Türkiye-based cyber security company providing digital forensics, compromise assessment, incident investigation, malware analysis and cyber incident examination services.
Frequently Asked Questions
What is digital forensics?
Digital forensics is the process of analysing incidents occurring on digital systems through technical evidence in order to establish how, when and to what extent they took place.
What is a compromise assessment?
A compromise assessment is the investigation of whether past or ongoing attacker activity exists on an organisation's systems.
What is the difference between a compromise assessment and a pentest?
A pentest tests whether an attacker can get into the system. A compromise assessment investigates whether an attacker is already inside.
Should digital forensics be carried out after a ransomware attack?
Yes. Forensic analysis is critical for understanding how the attack began, which systems it spread to and whether there was any data leakage.
Can deleted files be examined?
Depending on the circumstances and how the disk has been used, deleted files or file artefacts can be examined.
Why does memory forensics matter?
Some malicious software runs only in memory without writing a file to disk. Memory forensics helps examine activity of that kind.
Can digital forensics be used in legal proceedings?
Where correct evidence collection, integrity and chain of custody procedures are applied, digital evidence can be assessed in legal or administrative proceedings. Legal validity has to be assessed separately against the specific incident and the applicable legislation.
How long does a compromise assessment take?
The duration varies with the endpoints, servers and log sources to be examined and the scope of the incident.
If an Attack Has Occurred, the Most Critical Question Is: How Far Did It Get?
Detecting a security incident is the first step.
What really matters is establishing when the attacker entered the organisation, which systems they reached, which accounts they compromised and whether any data was taken out.
With the SecureSys digital forensics and compromise assessment service you can analyse the suspicious activity in your organisation in detail, build the attack timeline and define the real scope of the incident.
If you have a suspected security incident, a ransomware case, a data breach or a suspicion of attacker activity, get in touch with SecureSys to define your digital forensics and compromise assessment scope.
Want to learn more about this service?
Our expert team will reach out for a free consultation as soon as possible.