Activation and identification
Activation of the response plan, preservation of evidence and identification of the scope and of the first compromised system.
When the attack happens, we move fast: containment, eradication, recovery and a full forensic report of the incident.
Team available 24/7 for emergencies.
Incident response is the set of actions to contain, investigate and fix an attack or leak and return to normal operations with the least possible damage.
We prioritize critical incidents and start triage and remote containment as soon as possible, right after the NDA is signed. We have reverse engineered ransomware such as STOP/DJVU and REvil and restored operations for affected companies. The team is available 24/7 for emergencies.
A predictable flow, under NDA, with the client informed at every step.
Activation of the response plan, preservation of evidence and identification of the scope and of the first compromised system.
Network isolation, blocking of compromised accounts, disruption of lateral movement and root cause analysis.
Malware removal, system rebuild, credential reset and restoration validated with the business.
Support for internal, client and authority communication, post-incident analysis and updates to policies and playbooks.
Every engagement starts with a bilateral NDA. We do not disclose client names, vulnerabilities or incidents without written authorization, and sensitive communication uses encrypted channels (Signal and PGP).
Technical investigation of cyber incidents to determine how the attack happened, collect evidence and support legal action.
See the serviceWe analyze and reverse engineer malware to identify the origin of the attack, the behavior of the malicious code and the indicators of compromise.
See the serviceTabletop exercises and realistic crisis simulations to train technical and executive teams for the worst-case scenario.
See the serviceFast response, total confidentiality and field execution. No fluff.