What we preserve first, and why the order matters
The evidence acquisition sequence our responders follow in the first hour, and the reasoning behind it.
- Incident response
- Forensics
The single most expensive mistake in the first hour of an incident is not a wrong containment decision. It is destroying evidence that would have made every subsequent decision cheaper.
Volatile memory comes first, because it is the only place where an in-memory-only payload exists at all, and it disappears the moment someone follows the instinct to power the machine down. Isolating a host from the network preserves memory; shutting it down does not.
Logs come second, and specifically the ones with the shortest retention. Firewall, VPN and identity-provider logs frequently roll off within days. By the time a forensic team is formally engaged, the window that would have established initial access has often already closed.
Disk images come third. This surprises people, because imaging feels like the definitive forensic act — but disk is the least volatile artefact in the estate and will still be there tomorrow. Sequencing acquisition by volatility, rather than by perceived importance, is what keeps the timeline reconstructable.
See what an attacker sees
We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.
30 min
A scoping call, with an engineer rather than a sales rep.
What it costs
Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.
Under attack now?
Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.