Malware Forensics
What the code did, how it persisted, and what it reached.
Overview
Malware forensics establishes what the code did, how it persisted, and what it reached — not merely that it was present.
Detection tells you something ran. An investigation has to establish the payload’s capability, its persistence mechanism, the accounts and data within its reach, and whether it moved laterally. That distinction decides notification obligations, insurance position and remediation scope.
Analysis is conducted on preserved images and captured artefacts under the same chain-of-custody discipline as any other forensic exhibit, so findings remain usable in regulatory and legal proceedings.
Key outputs
- Payload capability and behaviour assessment
- Persistence and lateral-movement findings
- Extracted indicators of compromise for hunting
- Attack-chain reconstruction and attribution signals
- Containment and eradication recommendations
Malware and intrusion investigation
The sequence that turns a detection into an evidenced account of the intrusion.
Artefact Capture
Preservation of infected images, memory, and suspicious binaries with hash verification before any analysis is attempted.
Payload Inspection
Examination of malware and payloads recovered from email, endpoints and servers to establish capability and intent.
Persistence Detection
Identification of the mechanisms used to survive reboot and remediation — services, scheduled tasks, registry, and account footholds.
Lateral Movement Analysis
Authentication, event and network logs correlated to establish how far the intrusion reached inside the environment.
IOC Extraction & Threat Hunting
Indicators derived from the sample and swept across the estate to find related compromise that detection missed.
Attack-Chain Reconstruction
Entry point, execution, escalation and objective assembled into an evidenced narrative with a defensible timeline.
Attribution and infrastructure analysis
Where malware came from, and who stood behind the infrastructure that delivered it.
Cyber Incident Investigation
- Incident identification
- Attack analysis
- Intrusion detection
- Log analysis
- Network analysis
- Timeline reconstruction
- Root cause analysis
- Data exposure assessment
Email Forensic Analysis
- Detection of relay servers and anonymisation
- Malware and payload inspection
- Device and sender infrastructure tracing
Infrastructure & IP Intelligence
- ASN and ISP mapping
- Reputation and blacklist checks
- VPN / proxy / TOR identification
Domain & Identity Investigation
- Domain registration, creation timelines and ownership masking patterns
- Email footprinting across breaches, forums and OSINT sources
- Alias and identity linkage analysis
Related Capabilities
Forensics sits inside a wider integrity and risk practice.
Digital Forensics
Forensically sound acquisition, examination and evidence reporting.
Explore ServiceIncident Response
Detect, contain and investigate a live incident, then establish why it happened.
Explore ServiceInvestigations & Risk Intelligence
Corporate investigations, due diligence, asset tracing and dispute support.
Explore Service