The traces an intrusion leaves
Absence of alerts is not evidence of absence. These are the artefacts that are hard for an attacker to clean.
Persistence mechanisms
Scheduled tasks, services, startup entries and account changes that keep access alive across reboots.
Credential theft artefacts
Evidence of memory access, hash extraction and ticket abuse against your authentication systems.
Command and control traffic
Outbound connections to attacker infrastructure, including traffic tunnelled inside permitted protocols.
Lateral movement
Remote execution, administrative share access and authentication patterns that do not match how your staff work.
Staged data
Archives assembled in unusual locations, which is what exfiltration looks like just before it happens.
Suspicious accounts and privilege
Accounts created or elevated outside your change process, including ones that look plausible at a glance.
Tampered logging
Cleared, disabled or gapped audit trails, which are themselves a finding.
Known indicators
Current threat intelligence indicators checked against your environment and its retained history.
Anomalous behaviour
Access and process behaviour that deviates from the established baseline for that host or account.
Five phases, and a containment path if we find something
The engagement is designed to answer one question. If the answer is yes, it becomes an incident response engagement immediately.
Scheduled assessment
A defined engagement across an agreed scope, typically run annually or before a major event such as an acquisition or an audit.
Suspicion driven assessment
Fast mobilisation when something feels wrong but nothing is confirmed, with a direct path into full incident response.
Controls that work alongside it
Incident response
Where the engagement goes if the answer is yes.
SIEM
The telemetry that makes the next hunt faster and the next intrusion louder.
NDR
Retained traffic that turns a suspicion into a timeline.
