Find out exactly what the malware did — what files it accessed, what it sent out, how it got in, and whether anything else was affected.
A forensic investigation into what malware did on your system — not just removing it, but understanding what happened.
Removing malware stops the active threat. An investigation tells you what damage was done. Did it access your files? Did it send anything out? Were credentials captured? Did it spread to other devices on the network? For individuals, that answer might affect whether you need to change passwords or notify someone. For businesses, it may determine your legal obligations.
A malware investigation uses the same forensic methods used in corporate incident response — timeline analysis, memory analysis, network connection review, and artifact recovery. The result is a clear, documented picture of what happened, written in plain English so you know exactly where you stand.
A forensic investigation into every angle of the infection — documented and explained.
We find how the malware got in — phishing email, malicious download, drive-by exploit, or something else. Knowing the entry point is essential to preventing recurrence.
We reconstruct what the malware did and when — which files it accessed, what processes it ran, and what system changes it made. Timestamped and documented.
Did it send anything out? We review network connections and artifacts to assess whether data left the system — and if so, what kind and approximately when.
A written report of findings, in plain English. What happened, what the malware did, and what we recommend as next steps. Suitable for insurance or legal use if needed.
Describe the situation. We’ll let you know what the investigation would involve, how long it would take, and what it would cost.
We take a forensic image of the affected system — a bit-for-bit copy that preserves all evidence without altering the original. This is done before any cleanup.
We analyze the forensic image — timeline reconstruction, malware reverse engineering if needed, network artifact review, and documentation of findings.
You receive a written report and we walk you through what it means. We answer questions and tell you what steps we recommend based on what we found.
A forensic investigation report documents the incident in a way that can support an insurance claim, a police report, or legal proceedings. If you think your situation might go in that direction, mention it early — the way we collect and document evidence from the start affects how usable it is later.
If you just want the infection gone and don’t need to know what it did, a removal is sufficient. If you need to know what data was accessed, whether you have legal reporting obligations, or if you think something specific happened (stolen credentials, data exfiltration), an investigation is appropriate.
Yes, if we know at the outset that’s a possibility. Tell us early so we can follow proper evidence handling procedures from the start. The report documents methodology, findings, and chain of custody.