Court-ready DFIR. Daubert-aligned.
Digital incidents can become legal proceedings. Our forensic work acquires evidence in line with ISO/IEC 27037, maintains a documented chain of custody, uses validated techniques, and includes analyst testimony where required to support admissibility and expert scrutiny. The court makes the final admissibility determination.
ISO/IEC 27037ISO/IEC 27035ISO/IEC 27041NIST SP 800-86Daubert principlesGDPR Art. 33/34NIS2 / DORASEC Cyber
ACTIVE INCIDENT?
Do not power off systems or delete files. Our emergency response team is available 24/7/365. Contact us immediately to preserve evidence and limit adversary dwell time.
STANDARDS, LAW & REGULATION
Documentation designed for courtroom scrutiny.
International Standards
- ISO/IEC 27037:2012 · identification, collection, acquisition, and preservation of digital evidence
- ISO/IEC 27035-1:2023 · incident management principles and structured response process
- ISO/IEC 27041:2015 · assurance for digital evidence investigation methods and tools
- NIST SP 800-86 · integration of forensic techniques into incident response
- RFC 3227 · guidelines for evidence collection, archiving, and order of volatility
- SWGDE Standards · Scientific Working Group for Digital Evidence best practices
Court & Legal Admissibility
- Reproducible methodology · documented, repeatable techniques aligned to ISO/IEC 27037 and relevant Daubert principles, with method and tool limitations recorded for expert review
- Expert witness capability · expert-witness support where instructed by counsel, subject to the applicable court or tribunal accepting the proposed expert and evidence
- Legal hold & preservation notices · drafting support, litigation hold procedures, and e-discovery coordination
- International tribunal readiness · documentation structured for counsel review in cross-border arbitration and other international proceedings
- Attorney-client privilege · engagement structured at counsel’s direction where privilege is sought; availability and scope of privilege depend on applicable law
Regulatory Notification
- GDPR Art. 33 / 34 · factual incident timelines and technical evidence to support client and counsel notification decisions
- SEC cyber disclosure · factual technical summaries to support client and counsel materiality analysis and Form 8-K / 10-K drafting
- NIS2 / DORA · technical facts and incident timelines prepared for client and counsel reporting workflows
- HIPAA Breach Rule · factual breach-analysis documentation to support client and counsel risk assessment and notification work
- US state notification laws · technical facts organised for client and counsel jurisdictional analysis
- Direct liaison with internal and external legal counsel throughout all notification timelines and regulator correspondence
EVIDENCE INTEGRITY
Chain of custody, end to end.
Evidence handling follows a documented, auditable protocol from first contact through certified disposal. It is designed to support scrutiny under the requirements of the applicable proceeding and jurisdiction.
Acquisition
- Hardware write-blockers · used for supported physical media where appropriate; the acquisition method and any unavoidable source-system changes are documented by evidence type
- Bit-for-bit forensic imaging with validated tools selected for the evidence type, with tool versions and relevant limitations recorded
- Dual cryptographic hash verification · SHA-256 (authoritative) and MD5 (retained only for legacy-tool interoperability) computed and recorded at acquisition and at every subsequent transfer
- Volatile memory acquired before any shutdown using platform-appropriate acquisition tooling
- Full acquisition metadata logged: analyst identity, UTC timestamp, hardware identifiers, tool name and version
Custody & Storage
- Tamper-evident seals and unique evidence reference numbers applied to all physical media immediately upon acquisition
- AES-256 encrypted evidence containers · Access is restricted to named analysts. Shared credentials are not used
- Air-gapped analysis workstations: investigation infrastructure is never connected to client production networks
- Immutable audit trail · every access, transfer, and analysis action logged with analyst identity and UTC timestamp
- Physical evidence stored in access-controlled, environmentally monitored secure storage for the duration of the engagement
Verification & Disposition
- Hash re-verification at each analysis phase confirms evidence integrity has not been altered since acquisition
- Analysis is performed on working copies; originals remain preserved under evidence controls
- Formal evidence receipt and transfer documentation signed by all parties at each handoff
- Retention schedule defined per engagement agreement or court order; no open-ended storage
- Certified secure destruction · of evidence copies at end of retention, with witnessed destruction certificate provided to client
WHAT WE INVESTIGATE
Ransomware, intrusions, fraud, and multi-source forensics.
Incident Types
- Ransomware & extortion · including double-extortion, ransomware-as-a-service operators, and data leak site negotiation
- APT / nation-state intrusion · long-dwell, living-off-the-land, supply chain implant, and espionage campaigns
- Business Email Compromise (BEC) · account takeover, wire fraud redirection, and executive impersonation
- Insider threat & data exfiltration · privileged abuse, intellectual property theft, and sabotage investigations
- Data breach & unauthorised access · lateral movement mapping and complete scope determination for notification purposes
- Financial & cryptocurrency fraud · blockchain tracing, transaction forensics, and asset recovery support
- Industrial & OT incidents · ICS/SCADA impact assessment and evidence preservation in operational technology environments
Forensic Capabilities
- Memory forensics · live acquisition, malware detection, process injection, code injection, and rootkit identification
- Disk & file system forensics · deleted artefact recovery, anti-forensic detection, and deep multi-source timeline reconstruction
- Cloud forensics · cloud provider audit logs, SaaS platform event analysis, and control-plane investigation
- Network forensics · full-packet capture analysis, C2 beacon identification, and lateral movement reconstruction from flow and PCAP data
- Mobile forensics · iOS and Android acquisition (physical, logical, file-system) using validated mobile forensics tooling
- Malware analysis · static disassembly, dynamic sandbox execution, C2 infrastructure mapping, and detection rule development
- Threat actor attribution · TTP analysis mapped to MITRE ATT&CK, adversary infrastructure pivoting, and threat intelligence correlation
DELIVERABLES
Reports for engineers, lawyers, and regulators.
Technical Report
- Complete attack timeline with UTC-anchored events across all evidence sources
- Confirmed and assessed initial access vector(s)
- Full lateral movement, privilege escalation, and persistence path reconstruction
- Scope determination: confirmed affected vs. ruled-out systems and data
- Structured IOC package · hashes, IPs, domains, TTPs in STIX 2.1 / MISP format
- Custom YARA and Sigma detection rules for identified malware families and TTPs
- MITRE ATT&CK navigator layer with full TTP mapping and threat actor profile
Legal & Regulatory
- Court-ready evidentiary report · with documented methodology, tool validation records, and signed analyst declaration
- Complete chain of custody log and evidence register for all acquired items
- Expert witness brief and supporting affidavit prepared upon instruction of counsel
- Technical breach scope and affected-data analysis to support client and counsel assessment of notification obligations
- Draft regulatory factual summary (GDPR, SEC, NIS2, HIPAA) for client and counsel review before any submission
- Forensic examination certificate with cryptographic hash verification record
Executive & Remediation
- Executive summary: non-technical narrative suitable for board, regulator, and insurer communication
- Root cause analysis and contributing security control failures
- Prioritised containment and eradication checklist
- Strategic remediation roadmap with risk-ranked recommendations to prevent recurrence
- Post-incident lessons-learned facilitation session with technical and leadership teams
- Cyber insurance claim support documentation where applicable
HOW WE ENGAGE
Emergency or retainer.
Emergency Engagement
- Immediate triage · severity assessment and routing to a senior responder within 15 minutes; stakeholder identification and emergency NDA executed within the first hour
- Out-of-band comms established · encrypted communication channel activated immediately; no incident-related information transmitted via client infrastructure
- Volatile evidence preservation · immediate guidance on preservation actions; remote or on-site acquisition initiated to capture memory and live state before it degrades
- Parallel containment guidance · containment recommendations issued concurrently with evidence collection to limit adversary dwell and blast radius without destroying evidence
- Encrypted status cadence · secure briefings at agreed intervals throughout the incident; no gaps in communication during active crisis
- Final delivery & handover · complete technical and legal deliverable package with structured remediation handover and debrief
Retainer Engagement
- Contractual SLAs · acknowledgement, analyst assignment, and on-site response terms defined in the signed retainer or engagement agreement
- Pre-executed documentation · NDA, engagement letter, and evidence handling agreements signed before any incident occurs
- Environment familiarisation · asset inventory, crown jewels register, and network architecture reviewed and held in readiness prior to any incident
- Annual tabletop exercise · IR simulation included; validates playbooks and stakeholder readiness against realistic threat scenarios
- Priority queuing · retainer clients receive priority mobilisation over ad-hoc engagements during surge conditions
- Unused hours credit · unconsumed retainer hours roll over or credit future engagements per contract terms
Get a written proposal
Send scope + timeline. Initial response and next steps within 1 business day; proposal timing is confirmed after scoping.
Open the form →
Email a senior practitioner
Direct line for scoping questions. NDA available on request before you share details.
hello@grillisecurity.com →
Active incident?
24/7 incident line. Triage call + retainer set-up inside the hour for new engagements.
+372 5610 1641 →
