Incident response (CERT, CSIRT)
REDTEAM.PL CERT (RFC 2350) is a recognised incident response team and a member of Trusted Introducer, the largest international organisation bringing together CERT (Computer Emergency Response Team) units. We are listed on the official site of the European Union Agency for Cybersecurity (ENISA) as a Polish incident response team (CERT / CSIRT). Acting as a CSIRT (Computer Security Incident Response Team) we can provide immediate help when an incident occurs, advise on how to approach the problem to obtain the results you need, and carry out a reliable analysis of the event. We handle the work end to end – from correctly securing the data, through the analysis, to a final report describing the established details of the incident. To secure data quickly after an incident we also offer know-how support on how to properly preserve evidence on Windows and Linux systems. This means we do not hold up the business: affected machines can return to service before long without any negative impact on the analysis, while correctly secured evidence remains usable in court proceedings.
Securing digital evidence
The foundation of incident response is correctly securing the evidence on which the analysis is then performed. Incorrectly secured evidence leads to information being destroyed and may not only hinder the analysis but make it impossible altogether. In turn, an incorrectly performed analysis that fails to answer how the incident happened and what its consequences are can have far-reaching effects on information security and business continuity.
We will secure the evidence professionally, whether for further analysis or for the purposes of court proceedings. We will come on site to secure the evidence using dedicated hardware and software, or help you carry out the process correctly. The service can be performed both on a powered-off machine and on a running one – so-called live forensics, or live response.
By courtesy of Wydawnictwo Naukowe PWN, a descriptive excerpt from Adam Ziaja’s book on the correct way to secure data has been made available free of charge. For our clients we also provide a technical guide on how to secure evidence to professional standards.
Our publications on incident analysis
Court-appointed IT expert witness
Opinions as a court-appointed expert witness in computer science, from the list of the District Court in Warsaw (currently appointed until 2028), are available exclusively to authorised state bodies – and from more than one expert, as our team includes several. Our specialisation is cybersecurity (post-breach analysis, log analysis, hacking, cybercrime) and we take on work only within that scope. There is no legal possibility of issuing an expert witness opinion for any private entity (an individual, a company and so on). We do not provide consultations or advice in relation to litigation.
Why us? Knowledge and experience
As one of the few companies that do not deal exclusively with computer forensics, we have the software, the hardware and real competence backed by professional experience in this area. We use professional dedicated software, which is of much higher quality than free tools and translates directly into the speed and effectiveness of the analysis. We also use hardware write blockers (a device that makes writing to the disk impossible) to maintain the highest standards of safety when working on evidence, so that its full integrity is preserved. We hold court-appointed expert witness status in computer forensics, and can therefore issue binding expert opinions at the request of authorised state bodies.
Adam Ziaja is a co-author of several documents published by the European Union Agency for Cybersecurity (ENISA) for CSIRT teams, including a publication devoted to digital forensics.
We have equally broad experience in offensive cybersecurity, which helps us considerably in incident response. We understand hacking attacks very well, and that understanding goes directly into the quality of our post-breach analysis.
Incident analysis
Where a hacking breach has occurred, what matters most is time and the correct securing of evidence – not only for court purposes but also to answer the questions of how the breach happened and what operations were carried out. We advise against attempting to analyse a breach on your own, because of the real risk of destroying traces by overwriting important artefacts. We also perform analysis of targeted APT attacks.
Secure data erasure
We carry out irreversible erasure of data from physically undamaged media. In cases such as the sale or return of leased equipment we can remove data so that it cannot be recovered by any computer forensics software. The technique we use causes no physical damage, so the disks remain fit for further use.
Corporate espionage
We help detect and secure traces of corporate espionage where there is suspicion that trade secrets are being obtained by dishonest competitors. On one side by obtaining evidence of wrongdoing by disloyal employees, and on the other by analysing the infrastructure for breaches and information leaks.
Computer forensics training
We deliver computer forensics training for beginner, intermediate and advanced participants. Alongside classic courses we also offer tracks dedicated to the analysis of mobile devices and of video recordings, as well as product training on FTK (Forensic Toolkit) and X-Ways Forensics.
Recovery of encrypted data
We attempt to recover data encrypted by cryptolocker-type malware. Malware of this kind works by encrypting important data and then demanding a ransom. How quickly you react after the attack affects how much data can be recovered.
Log, disk, RAM and network traffic analysis
We analyse digital information of every kind: examination of multiple evidence disks, log analysis (for example Windows event logs), acquisition and analysis of RAM memory, and network traffic analysis.
Ransomware attack analysis
We analyse ransomware attacks, including cases where data has already been encrypted. We secured servers used in attacks by the Sodinokibi / REvil APT group and published the TTPs of the Black Kingdom APT group.
Phishing analysis
We analyse attacks such as phishing campaigns and targeted, advanced spear-phishing. We understand very well how attacks of this kind are carried out, because we also provide social engineering testing as a service.
Malware analysis
We perform malware analysis, from behavioural through to static. We are also able to identify malicious software on a disk through deep analysis of its contents.
“Practical post-breach analysis”
Adam Ziaja is a court-appointed expert witness and the author of the first Polish technical academic publication on digital forensics and incident response (DFIR), titled “Praktyczna analiza powłamaniowa” (ISBN 9788301193478). It was published by Wydawnictwo Naukowe PWN and carries a positive review by another court-appointed expert, Assoc. Prof. J. Kosiński of the Police Academy in Szczytno. The book covers technical subjects such as securing data, analysing hacking attacks and detecting backdoors and rootkits. The publication documents our incident response competence, which follows directly from extensive experience in data analysis, detection of malicious activity and simulation of hacking attacks.