Digital Forensics & Incident Response

Digital Forensics &
Incident Response

Digital forensics and incident response means collecting and securing digital evidence to professional standards, analysing incidents such as hacking attacks (post-breach analysis), examining artefacts of user activity and recovering data. We hold court-appointed expert witness status.

Get a quote

Report an Incident

If your organization needs assistance for a possible incident or security breach, please contact our incident response team at cert@redteam.pl (PGP, RFC 2350).

Know our SOC / CERT

SOC

We offer both ad hoc assistance during incidents and a proactive service of constant 24/7 monitoring of IT resources in terms of cybersecurity (threat intelligence and threat hunting using RedEye) and immediate response to incidents (computer forensics and intrusion analysis). We invite you to familiarize yourself with the SOC-as-a-Service service offered by our Security Operations Center (SOC) team.

Incident analysis and post-breach analysis

Our broad expertise allows us to deliver computer forensics services with particular emphasis on cybersecurity, that is DFIR (Digital Forensics and Incident Response). We hold court-appointed expert witness status on the list of the District Court in Warsaw and real hands-on experience in this field – we have taken part in securing evidence at crime scenes, and we use high-grade hardware and commercial software dedicated to this discipline. Our experience of well over a decade in this area of cybersecurity is backed by recognised publications, including authorship of a book published by Wydawnictwo Naukowe PWN and co-authorship of several ENISA documents (the European Union Agency for Cybersecurity), among them training material on digital forensics and incident analysis issued by that EU agency for incident response teams (CERT). We have carried out post-breach analysis over the last dozen or so years for dozens of Polish and international organisations.

Incident response (CERT, CSIRT)

REDTEAM.PL CERT (RFC 2350) is a recognised incident response team and a member of Trusted Introducer, the largest international organisation bringing together CERT (Computer Emergency Response Team) units. We are listed on the official site of the European Union Agency for Cybersecurity (ENISA) as a Polish incident response team (CERT / CSIRT). Acting as a CSIRT (Computer Security Incident Response Team) we can provide immediate help when an incident occurs, advise on how to approach the problem to obtain the results you need, and carry out a reliable analysis of the event. We handle the work end to end – from correctly securing the data, through the analysis, to a final report describing the established details of the incident. To secure data quickly after an incident we also offer know-how support on how to properly preserve evidence on Windows and Linux systems. This means we do not hold up the business: affected machines can return to service before long without any negative impact on the analysis, while correctly secured evidence remains usable in court proceedings.

Securing digital evidence

The foundation of incident response is correctly securing the evidence on which the analysis is then performed. Incorrectly secured evidence leads to information being destroyed and may not only hinder the analysis but make it impossible altogether. In turn, an incorrectly performed analysis that fails to answer how the incident happened and what its consequences are can have far-reaching effects on information security and business continuity.

We will secure the evidence professionally, whether for further analysis or for the purposes of court proceedings. We will come on site to secure the evidence using dedicated hardware and software, or help you carry out the process correctly. The service can be performed both on a powered-off machine and on a running one – so-called live forensics, or live response.

By courtesy of Wydawnictwo Naukowe PWN, a descriptive excerpt from Adam Ziaja’s book on the correct way to secure data has been made available free of charge. For our clients we also provide a technical guide on how to secure evidence to professional standards.

Court-appointed IT expert witness

Opinions as a court-appointed expert witness in computer science, from the list of the District Court in Warsaw (currently appointed until 2028), are available exclusively to authorised state bodies – and from more than one expert, as our team includes several. Our specialisation is cybersecurity (post-breach analysis, log analysis, hacking, cybercrime) and we take on work only within that scope. There is no legal possibility of issuing an expert witness opinion for any private entity (an individual, a company and so on). We do not provide consultations or advice in relation to litigation.

Why us? Knowledge and experience

As one of the few companies that do not deal exclusively with computer forensics, we have the software, the hardware and real competence backed by professional experience in this area. We use professional dedicated software, which is of much higher quality than free tools and translates directly into the speed and effectiveness of the analysis. We also use hardware write blockers (a device that makes writing to the disk impossible) to maintain the highest standards of safety when working on evidence, so that its full integrity is preserved. We hold court-appointed expert witness status in computer forensics, and can therefore issue binding expert opinions at the request of authorised state bodies.

Adam Ziaja is a co-author of several documents published by the European Union Agency for Cybersecurity (ENISA) for CSIRT teams, including a publication devoted to digital forensics.

We have equally broad experience in offensive cybersecurity, which helps us considerably in incident response. We understand hacking attacks very well, and that understanding goes directly into the quality of our post-breach analysis.

REDTEAM.PL digital forensics laboratory

Incident analysis

Where a hacking breach has occurred, what matters most is time and the correct securing of evidence – not only for court purposes but also to answer the questions of how the breach happened and what operations were carried out. We advise against attempting to analyse a breach on your own, because of the real risk of destroying traces by overwriting important artefacts. We also perform analysis of targeted APT attacks.

Secure data erasure

We carry out irreversible erasure of data from physically undamaged media. In cases such as the sale or return of leased equipment we can remove data so that it cannot be recovered by any computer forensics software. The technique we use causes no physical damage, so the disks remain fit for further use.

Corporate espionage

We help detect and secure traces of corporate espionage where there is suspicion that trade secrets are being obtained by dishonest competitors. On one side by obtaining evidence of wrongdoing by disloyal employees, and on the other by analysing the infrastructure for breaches and information leaks.

Computer forensics training

We deliver computer forensics training for beginner, intermediate and advanced participants. Alongside classic courses we also offer tracks dedicated to the analysis of mobile devices and of video recordings, as well as product training on FTK (Forensic Toolkit) and X-Ways Forensics.

Recovery of encrypted data

We attempt to recover data encrypted by cryptolocker-type malware. Malware of this kind works by encrypting important data and then demanding a ransom. How quickly you react after the attack affects how much data can be recovered.

Log, disk, RAM and network traffic analysis

We analyse digital information of every kind: examination of multiple evidence disks, log analysis (for example Windows event logs), acquisition and analysis of RAM memory, and network traffic analysis.

Ransomware attack analysis

We analyse ransomware attacks, including cases where data has already been encrypted. We secured servers used in attacks by the Sodinokibi / REvil APT group and published the TTPs of the Black Kingdom APT group.

Phishing analysis

We analyse attacks such as phishing campaigns and targeted, advanced spear-phishing. We understand very well how attacks of this kind are carried out, because we also provide social engineering testing as a service.

Malware analysis

We perform malware analysis, from behavioural through to static. We are also able to identify malicious software on a disk through deep analysis of its contents.

“Practical post-breach analysis”

Praktyczna analiza powłamaniowa — book by Adam Ziaja of REDTEAM.PL published by PWN

Adam Ziaja is a court-appointed expert witness and the author of the first Polish technical academic publication on digital forensics and incident response (DFIR), titled “Praktyczna analiza powłamaniowa” (ISBN 9788301193478). It was published by Wydawnictwo Naukowe PWN and carries a positive review by another court-appointed expert, Assoc. Prof. J. Kosiński of the Police Academy in Szczytno. The book covers technical subjects such as securing data, analysing hacking attacks and detecting backdoors and rootkits. The publication documents our incident response competence, which follows directly from extensive experience in data analysis, detection of malicious activity and simulation of hacking attacks.

Explore Our Offer

We deliver advanced technical consulting services covering multiple aspects of cybersecurity from red team to blue team. Thanks to a diverse experience in IT security we are able to look at a wider perspective during engagements. Our abilities come from many years of work experience in cybersecurity and are confirmed with certificates, publications, advisories and references from our customers.

REDTEAM.PL client references