Important notice: BSides Curitiba 2026 · October 17 · PUCPR · Get your ticket
← All services// Services · Incidents

Incident Management

When the attack happens, we move fast: containment, eradication, recovery and a full forensic report of the incident.

Team available 24/7 for emergencies.

// What it is

What it is about

Incident response is the set of actions to contain, investigate and fix an attack or leak and return to normal operations with the least possible damage.

We prioritize critical incidents and start triage and remote containment as soon as possible, right after the NDA is signed. We have reverse engineered ransomware such as STOP/DJVU and REvil and restored operations for affected companies. The team is available 24/7 for emergencies.

// When to hire

When it makes sense

  • Ransomware, encrypted systems or operations at a standstill.
  • Suspected breach, unauthorized access or data leak.
  • Compromised corporate or executive accounts.
  • When you need to assess notification to the ANPD and to data subjects (LGPD).
// How we do it

From first contact to delivery

A predictable flow, under NDA, with the client informed at every step.

01

Activation and identification

Activation of the response plan, preservation of evidence and identification of the scope and of the first compromised system.

02

Containment and investigation

Network isolation, blocking of compromised accounts, disruption of lateral movement and root cause analysis.

03

Eradication and recovery

Malware removal, system rebuild, credential reset and restoration validated with the business.

04

Communication and improvement

Support for internal, client and authority communication, post-incident analysis and updates to policies and playbooks.

// Deliverables

What you get

  • Full forensic report of the incident.
  • Indicators of compromise to block the threat in other environments.
  • Remediation and continuous improvement plan.

Every engagement starts with a bilateral NDA. We do not disclose client names, vulnerabilities or incidents without written authorization, and sensitive communication uses encrypted channels (Signal and PGP).

// Related services

You may also like

Forensics

Digital Forensics

Technical investigation of cyber incidents to determine how the attack happened, collect evidence and support legal action.

See the service
Analysis

Malware Reverse Engineering

We analyze and reverse engineer malware to identify the origin of the attack, the behavior of the malicious code and the indicators of compromise.

See the service
Training

Crisis Simulations (Cyber Drills)

Tabletop exercises and realistic crisis simulations to train technical and executive teams for the worst-case scenario.

See the service
// Ready to act?

Let's protect what is yours.

Fast response, total confidentiality and field execution. No fluff.

Cookies and privacy

NecessaryAlways on
Metrics