Cybersecurity IT Forensik
Incidents & Response

After the attack: Secure evidence, determine the cause.

We analyze compromised systems, reconstruct the entire course of the attack, and secure evidence admissible in court. From endpoints to the cloud to mobile devices.

Case File FA-2024-0847 ACTIVE
HP EliteBook 845 G8
Exhibit 0847-A · Laptop
IMAGING
72%
Disk image · write-blocked · SHA-256 pending
iPhone 14 Pro
Exhibit 0847-B · Smartphone
SAVE
100%
Extraction complete · Hash verified · Admissible in court
Dell R740 Server
Exhibit 0847-C · Server
WAITING LINE
-
Planned: RAM dump + network logs + event log
The problem

What happens after an attack is more important than the attack itself.

The first few hours after a security incident are critical. Evidence that isn’t properly secured is worthless in court. Incomplete analyses leave vulnerabilities unaddressed. And without a clear analysis of the root causes, the same thing will happen again.

Many companies react to an attack instinctively: restarting systems, checking data, and resetting passwords. Each of these actions can destroy evidence and make legal action permanently impossible.

72h
NIS2 reporting requirement following incident detection
60%
initial forensic procedures are being performed incorrectly

Evidence was improperly secured

Anyone who proceeds without using forensic methods destroys evidence. Restarting live systems, overwriting logs, copying files—all of these actions make legal action impossible.

The cause remains unclear

Without a thorough analysis, the initial point of entry often remains unknown. The gateway remains open, and the next attack could follow at any time.

Government agencies and insurance companies require proof

NIS2 reporting requirements, cyber insurance, and criminal prosecution require complete documentation that is verifiably accurate and complies with recognized standards.

01 Forensic Services

Comprehensive analysis. Documentation admissible in court.

We secure and analyze digital evidence in accordance with recognized forensic standards. Every step is documented, and every finding is verifiable and admissible in court.

Endpoint & Server
Windows · Linux · macOS · Timeline
Cloud Forensics
Microsoft 365 · Azure · AWS · Logs
Mobile & IoT
Smartphones · Tablets · Wearables · IoT
Network & Logs
Firewalls · Server Logs · Traffic · SIEM
Fuse
RAM dump before system shutdown
Forensic disk images (write-protected)
Cryptographic Hash Verification
Analysis
Complete timeline of the attack
Identification of the entry point
Lateral Movement Reconstruction
Documentation
Forensic Report in accordance with ISO 27037
Suitable for government agencies and courts
NIS2 Reporting Requirements Documentation
Chain of Custody: Preserving Evidence Step by Step
EVD-01
Back up the device
Disconnect from the network, do not delete anything, RAM dump
EVD-02
Disk image
Write-protected, forensic copy created
EVD-03
Hash verification
SHA-256, integrity fully verified
EVD-04
Analysis
Timeline, emergence, and spread reconstructed
EVD-05
Report
ISO 27037, admissible in court
Is this an emergency? Call us now.
Immediate initial support over the phone. No waiting on hold, no ticket system.
02 Procedure

From the initial report to a report admissible in court.

Forensic investigations follow a clearly defined process. Any deviation can destroy evidence and make legal action impossible.

Forensic Investigation Process

01

Initial Report & Initial Security Measures

You report the incident. We will immediately provide instructions over the phone on what to do and what you must not do under any circumstances.

0–2 hours
02

Device Return by Mail

You must hand over or ship the devices in question to us, ensuring they are physically secured and accompanied by a handover report. Packaging and transport must comply with forensic requirements to ensure that the chain of custody remains unbroken.

By arrangement
03

Forensic evidence collection in the laboratory

RAM dumps, write-blocked disk images, and log data are cryptographically secured. SHA-256 hash values serve as evidence of the integrity of all pieces of evidence in court.

2–8 hours
04

Forensic Analysis and Reconstruction

Complete reconstruction of the attack sequence. We identify the point of entry, the scope of the attack, all affected systems, and the total damage.

1–5 days
05

Final Forensic Report

A comprehensive document containing a timeline, findings, a chain of evidence, and recommendations for action. Suitable for use by government agencies, courts, and insurance companies.

1–2 days
06

Aftercare and hardening

Upon request, we can assist with addressing vulnerabilities and hardening systems to ensure that the next attack fails.

optional
NIS2 requires reporting within 72 hours.
Our forensic report provides all the information the authorities need for the initial report.
Schedule an initial consultation
Why ITanic

What sets our forensic services apart from others.

Forensics is not a service where "good enough" is acceptable. Errors in the preservation of evidence are irreversible.

Practical experience. Not textbook methodology.

Ransomware attacks, insider threats, APT campaigns: we’ve analyzed them forensically. We know what works from real-world cases, not from certification documents.

Reports that stand up in court.

ISO 27037, unbroken chain of evidence, cryptographic verification. Our reports have already been used in criminal proceedings, not just in internal analyses.

72 hours. We’ll deliver what NIS2 requires.

Our final report is structured to meet regulatory reporting requirements. All required information for the initial report and the follow-up report is included and available by the deadline.

Forensics and incident response, all under one roof.

While we secure evidence, our IR team can work in parallel to stabilize operations. No time is lost due to coordination between external teams.

FAQ

Frequently asked questions.

Acute incident
We're under attack right now. What should we do immediately?
+
Call us immediately. Do not shut down the affected systems: a RAM dump taken before shutdown preserves volatile evidence that will be lost forever after a reboot. Isolate compromised systems from the network, but do not delete anything or change any settings until we assist you.
Do we need to shut down the affected systems?
+
Not immediately, and not without forensic preparation. A RAM dump must be created before the device is powered down. We will guide you through this step over the phone to ensure that no evidence is lost.
Forensic Report
Is the report really admissible in court?
+
Yes, provided that the preservation of evidence was carried out correctly in accordance with ISO 27037. Our reports document the complete chain of custody, all analytical steps, and the cryptographic verification of the evidence. They have already been used in criminal proceedings.
Does the report cover the NIS2 reporting requirements?
+
Yes. We structure the report to ensure that it includes all the required information for the initial 72-hour report and the subsequent final report to the relevant authority. Upon request, we can also provide direct assistance with communicating with the authorities.
Procedure and Equipment
What devices can you analyze forensically?
+
We analyze Windows, Linux, and macOS systems, servers, smartphones and tablets (iOS and Android), network devices, cloud environments (Microsoft 365, Azure, AWS), as well as IoT devices and wearables. If you’re not sure whether your device is included, just give us a call.
How do I send in a device for analysis?
+
After a brief phone call, we will provide you with detailed instructions on how to package and transport the items in accordance with forensic standards. We ensure that the chain of custody is fully documented from the very beginning. We will send you the address and a handover report directly.
How long does a forensic examination take?
+
That depends on the scope of the project. A single device can often be secured and analyzed within one to two days. For multiple systems, cloud environments, or complex ransomware incidents, we estimate that it will take five to ten days to complete the final report. We will provide a realistic estimate during the initial consultation.
Next step
The matter has been resolved. Now we need to make sure it doesn't happen again.
View Detection & Response

Investigate incidents. Secure evidence. Move forward.

In an emergency, every hour counts. Contact us now to discuss your case, or send us the affected devices for analysis.

Available immediately, even in the event of an emergency
Evidence preservation in compliance with ISO 27037
NIS2 reporting requirements met