Englishالعربية Soon
Under attack?
Active incident right now?Call first. File the form afterwards.
+962 6 55 333 17
DFIR · Digital forensics and incident response

When prevention fails, the clock is the only thing that matters.

Our team contains the incident, preserves the evidence, establishes what actually happened and closes the route in. Retainer clients get a responder who already knows their environment before the call is made.

Before you call, if you can
Do not power off affected machines
Do not begin rebuilding yet
Preserve logs and disable log rotation
Note who noticed what, and when
Keep discussion off the affected systems
The first week

What happens, and when

Timings below assume a retainer. Without one, the first two rows take longer because we are learning your environment while the attacker is still in it.

T+0

Call received

A responder is on the line, not a ticket queue. We establish what you are seeing, what is still running and what must not be touched.

T+1h

Triage and scoping

Initial scope agreed: which systems, which accounts, which data. Evidence preservation starts before anything is rebuilt.

T+4h

Containment

Affected hosts isolated while remaining reachable to us, accounts disabled, attacker access cut. Business continuity decisions made with you, not for you.

Day 1

Forensics

Memory, disk and log evidence collected and analysed. The who, the what and the how, established from artefacts rather than assumption.

Week 1

Root cause and closure

The entry point identified and closed, a written timeline delivered, and the controls that would have caught it earlier specified.

Forensic capability

What we can establish from what is left behind

An incident report that says “probably ransomware” is not a report. These are the questions we answer with evidence.

Entry

How they got in

The initial vector identified from artefacts: the phishing message, the exploited service, the reused credential, the supplier connection.

Dwell

How long they were there

First and last observed activity, so you know whether this was hours or months and what was accessible throughout.

Reach

What they touched

Systems accessed, accounts used, data staged or moved, and whether exfiltration actually occurred or was only attempted.

Tooling

What they used

Malware, remote access tooling and living-off-the-land techniques identified and, where possible, attributed to a known group.

Persistence

What they left behind

Scheduled tasks, services, accounts and implants located and removed, so the rebuild does not reinstate the attacker.

Obligation

What you must report

A factual timeline and impact assessment in the form your regulator, insurer and legal counsel each need.

Retainers

The difference a retainer makes, line by line

Without one you are negotiating a contract while an attacker is inside your network. That negotiation has cost clients more than the retainer would have.

 
No retainer
Standard
Premium
Response time commitment
Best effort
4 hours
1 hour
Environment documented in advance
,
Yes
Yes
Named responder assigned
,
Yes
Yes
Forensic tooling pre-deployed
,
Optional
Yes
Annual tabletop exercise
,
1
2
IR plan and playbook review
,
Annual
Twice yearly
Hours included
Billed hourly
Pre-purchased block
Pre-purchased block
Out-of-hours cover
,
24/7
24/7 priority
Related

What reduces the odds of needing us

Managed SOC

Most incidents we attend were visible in the logs for weeks. Somebody has to be reading them.

Compromise assessment

If you suspect you are already compromised but have no active alert, start here.

EDR and XDR

Retained endpoint telemetry is what makes the forensic timeline possible at all.

Put a team on standby before you need one.

A retainer takes a week to set up and changes the first four hours of your worst day.