24/7 forensics hotline
+31 20 716 5487Digital forensics by Neo Security
Need evidence for legal action? Investigating a data breach? We reconstruct and analyze digital incidents using forensically sound methods.
We analyze RAM, hard drives, network traffic, browser history, email history, and databases to ensure a solid reconstruction of the incident, timeline, and facts. We deliver both legal and technical reports. Moreover, we ensure it's clear what happened, even if you're not an IT Law or Forensics specialist.
50+ times
Analysis performed
100%
Court-admissible evidence
What is digital forensics?
Digital forensics is the scientific examination of digital traces. We use specialized tools and methodologies to preserve, analyze, and reconstruct data - always following strict chain-of-custody procedures. We specialize in reconstructing digital incidents.
Forensic capabilities
Data recovery & analysis
- ▸Deleted file recovery (NTFS/ext4/APFS)
- ▸RAM memory analysis & volatile data capture
- ▸Browser artifacts & web history reconstruction
- ▸Email forensics (PST/OST/MBOX analysis)
- ▸Database reconstruction (SQL/NoSQL)
- ▸Encrypted drive analysis (BitLocker/FileVault)
Network & system Forensics
- ▸Network traffic analysis (PCAP deep dive)
- ▸Log correlation across multiple systems
- ▸Active Directory forensics & timeline analysis
- ▸Cloud forensics (AWS/Azure/Google Cloud)
- ▸Container & Kubernetes forensics
- ▸Mobile device forensics (iOS/Android)
Malware & incident analysis
- ▸Malware reverse engineering
- ▸Ransomware strain identification
- ▸C2 infrastructure mapping
- ▸Lateral movement reconstruction
- ▸Data exfiltration path analysis
- ▸APT attribution & TTP mapping
“Every byte counts. We use Volatility for memory forensics, Plaso for timeline analysis, and have the best correlation toolkits ready. The difference between 'thinking you know' and 'forensically proving' is what wins court cases.”
Benjamin Korper
CEO & Co-Founder
When we conduct forensic investigation, we follow this methodology
Initial Response
Activities
- •Remote triage via eDR/forensic agents
- •Memory dump acquisition
- •Critical log preservation
- •Chain of custody establishment
Deliverable
Preliminary findings & evidence preservation
Deep dive analysis
Activities
- •Timeline reconstruction (Plaso/log2timeline)
- •Registry & artifact analysis
- •File system forensics
- •Network forensics & PCAP analysis
Deliverable
Technical forensic report with iOCs
Business Impact assessment
Activities
- •Data classification & exposure analysis
- •Regulatory impact assessment
- •Attribution confidence levels
- •Remediation roadmap
Deliverable
Executive report & legal documentation
Real cases from our forensic practice
Real incidents, concrete results. Details anonymized for confidentiality.
Insider Threat - IP theft
Senior engineer suspected of stealing source code before joining competitor
Technical approach
PowerShell history analysis + Git repo access logs + USB device tracking
Key findings
3GB of proprietary code exfiltrated via personal GitHub over 6 months
€1.2M settlement, criminal prosecution initiated
48 hours to conclusive evidence
Ransomware investigation
Manufacturing firm hit by targeted ransomware, €500K ransom demand
Technical approach
Memory forensics + network traffic analysis + backup integrity verification
Key findings
Initial access via unpatched Fortinet VPN, 14-day dwell time before encryption
Full recovery without ransom payment, insurance claim approved
72 hours to full incident reconstruction
Financial fraud detection
CFO suspected of manipulating financial records before acquisition
Technical approach
SAP change logs + email pattern analysis + deleted file recovery
Key findings
€3.2M in hidden liabilities discovered through recovered spreadsheets
Acquisition price adjusted, legal action against former CFO
5 days comprehensive investigation
Enterprise-Grade forensic tooling
Acquisition tools
Analysis platforms
Specialized tools
Custom forensic-analysis tooling development
Besides commercial tools, we develop custom Python scripts and tooling for specific forensic challenges. From automated log correlation to custom artifact parsers for proprietary formats.
When to engage Digital Forensics?
Incident Response
- ▸Ransomware attack - need for attribution
- ▸Data breach - extent determination
- ▸Insider threat - evidence collection
- ▸Fraud investigation - financial forensics
Proactive Forensics
- ▸M&A due diligence - IT asset verification
- ▸Compliance audits - data handling verification
- ▸Employee exit - sensitive data checks
- ▸Legal disputes - evidence preservation
Every byte tells a story
Digital evidence disappears quickly. RAM is overwritten, logs rotate, timestamps change. The sooner we start, the more complete the story.
Transparent forensic services
Incident Response
€275/hour
24/7 availability, 4-hour minimum
Forensic investigation
€225/hour
Planned investigations, detailed reporting
Expert witness
€350/hour
Court testimony & legal support
What is included?
Digital Evidence. Legal Certainty.
From volatile memory to deleted files, from network traffic to cloud artifacts - we reconstruct the digital truth. Court-admissible, technically sound, business-focused.