(210) 560-0286·[email protected]
San Antonio & nationwide remote·Evenings & weekends
Home/Services/Malware investigations
Service

Malware investigations.

Find out exactly what the malware did — what files it accessed, what it sent out, how it got in, and whether anything else was affected.

Turnaround
3 – 7 business days
How
In person or remote
Good for
Individuals & businesses
Price
From $250 — quoted per job
01

What it is.

A forensic investigation into what malware did on your system — not just removing it, but understanding what happened.

Removing malware stops the active threat. An investigation tells you what damage was done. Did it access your files? Did it send anything out? Were credentials captured? Did it spread to other devices on the network? For individuals, that answer might affect whether you need to change passwords or notify someone. For businesses, it may determine your legal obligations.

A malware investigation uses the same forensic methods used in corporate incident response — timeline analysis, memory analysis, network connection review, and artifact recovery. The result is a clear, documented picture of what happened, written in plain English so you know exactly where you stand.

02

What’s included.

A forensic investigation into every angle of the infection — documented and explained.

01
Entry point analysis

We find how the malware got in — phishing email, malicious download, drive-by exploit, or something else. Knowing the entry point is essential to preventing recurrence.

02
Activity timeline

We reconstruct what the malware did and when — which files it accessed, what processes it ran, and what system changes it made. Timestamped and documented.

03
Data exfiltration review

Did it send anything out? We review network connections and artifacts to assess whether data left the system — and if so, what kind and approximately when.

04
Documented report

A written report of findings, in plain English. What happened, what the malware did, and what we recommend as next steps. Suitable for insurance or legal use if needed.

03

How it works.

01

Free consultation

No obligation

Describe the situation. We’ll let you know what the investigation would involve, how long it would take, and what it would cost.

02

Evidence collection

In person preferred

We take a forensic image of the affected system — a bit-for-bit copy that preserves all evidence without altering the original. This is done before any cleanup.

03

Forensic analysis

3 – 7 business days

We analyze the forensic image — timeline reconstruction, malware reverse engineering if needed, network artifact review, and documentation of findings.

04

Report and debrief

Written documentation

You receive a written report and we walk you through what it means. We answer questions and tell you what steps we recommend based on what we found.

04

Common questions.

Do I need an investigation, or just a removal?

If you just want the infection gone and don’t need to know what it did, a removal is sufficient. If you need to know what data was accessed, whether you have legal reporting obligations, or if you think something specific happened (stolen credentials, data exfiltration), an investigation is appropriate.

Is the investigation report usable in court or for insurance?

Yes, if we know at the outset that’s a possibility. Tell us early so we can follow proper evidence handling procedures from the start. The report documents methodology, findings, and chain of custody.

Get help now

Tell us what’s going on.

Send a few details and a certified specialist replies within 24 hours — sooner during evening and weekend hours.

Call or text(210) 560-0286
ServingSan Antonio & surrounding areas · nationwide remote