Service overview
What this service is designed to establish
Provides authorised acquisition and analysis of computer, drive, file-system and system artefacts relevant to a defined incident or dispute.
The first task is to convert a broad concern into specific questions that can be investigated responsibly. The method, duration and deliverables then follow from those questions—not from assumptions about what the answer should be.
Questions the engagement may address
Which devices and users are in scope?
What event or activity is being tested?
Must the original media remain unchanged?
What logs, files or timestamps may corroborate events?
