Skip to main content

24/7 forensics hotline

+31 20 716 5487

Digital forensics by Neo Security

Need evidence for legal action? Investigating a data breach? We reconstruct and analyze digital incidents using forensically sound methods.

We analyze RAM, hard drives, network traffic, browser history, email history, and databases to ensure a solid reconstruction of the incident, timeline, and facts. We deliver both legal and technical reports. Moreover, we ensure it's clear what happened, even if you're not an IT Law or Forensics specialist.

50+ times

Analysis performed

100%

Court-admissible evidence

What is digital forensics?

Digital forensics is the scientific examination of digital traces. We use specialized tools and methodologies to preserve, analyze, and reconstruct data - always following strict chain-of-custody procedures. We specialize in reconstructing digital incidents.

Write-blockers for data integrity
Cryptographic hashing (SHA-256/SHA-512/FIPS 186-5 compliant secure hashes)
Court-admissible documentation

Forensic capabilities

Data recovery & analysis

  • Deleted file recovery (NTFS/ext4/APFS)
  • RAM memory analysis & volatile data capture
  • Browser artifacts & web history reconstruction
  • Email forensics (PST/OST/MBOX analysis)
  • Database reconstruction (SQL/NoSQL)
  • Encrypted drive analysis (BitLocker/FileVault)

Network & system Forensics

  • Network traffic analysis (PCAP deep dive)
  • Log correlation across multiple systems
  • Active Directory forensics & timeline analysis
  • Cloud forensics (AWS/Azure/Google Cloud)
  • Container & Kubernetes forensics
  • Mobile device forensics (iOS/Android)

Malware & incident analysis

  • Malware reverse engineering
  • Ransomware strain identification
  • C2 infrastructure mapping
  • Lateral movement reconstruction
  • Data exfiltration path analysis
  • APT attribution & TTP mapping

Every byte counts. We use Volatility for memory forensics, Plaso for timeline analysis, and have the best correlation toolkits ready. The difference between 'thinking you know' and 'forensically proving' is what wins court cases.

Benjamin Korper

CEO & Co-Founder

When we conduct forensic investigation, we follow this methodology

1

Initial Response

0-4 hours

Activities

  • Remote triage via eDR/forensic agents
  • Memory dump acquisition
  • Critical log preservation
  • Chain of custody establishment

Deliverable

Preliminary findings & evidence preservation

2

Deep dive analysis

2-7 days

Activities

  • Timeline reconstruction (Plaso/log2timeline)
  • Registry & artifact analysis
  • File system forensics
  • Network forensics & PCAP analysis

Deliverable

Technical forensic report with iOCs

3

Business Impact assessment

1-3 days

Activities

  • Data classification & exposure analysis
  • Regulatory impact assessment
  • Attribution confidence levels
  • Remediation roadmap

Deliverable

Executive report & legal documentation

Real cases from our forensic practice

Real incidents, concrete results. Details anonymized for confidentiality.

Insider Threat - IP theft

Senior engineer suspected of stealing source code before joining competitor

Technical approach

PowerShell history analysis + Git repo access logs + USB device tracking

Key findings

3GB of proprietary code exfiltrated via personal GitHub over 6 months

Business Impact:

€1.2M settlement, criminal prosecution initiated

Time to evidence:

48 hours to conclusive evidence

Ransomware investigation

Manufacturing firm hit by targeted ransomware, €500K ransom demand

Technical approach

Memory forensics + network traffic analysis + backup integrity verification

Key findings

Initial access via unpatched Fortinet VPN, 14-day dwell time before encryption

Business Impact:

Full recovery without ransom payment, insurance claim approved

Time to evidence:

72 hours to full incident reconstruction

Financial fraud detection

CFO suspected of manipulating financial records before acquisition

Technical approach

SAP change logs + email pattern analysis + deleted file recovery

Key findings

€3.2M in hidden liabilities discovered through recovered spreadsheets

Business Impact:

Acquisition price adjusted, legal action against former CFO

Time to evidence:

5 days comprehensive investigation

Enterprise-Grade forensic tooling

Acquisition tools

FTK Imager
dd/dcfldd
Guymager
Magnet AXIOM (memory acquisition)

Analysis platforms

Autopsy/Sleuth Kit
Volatility 3 (memory analysis)
SIFT Workstation

Specialized tools

IDA Pro (reverse engineering)
Wireshark (network traffic analysis)
Plaso (timeline analysis)
YARA (IOC matching)

Custom forensic-analysis tooling development

Besides commercial tools, we develop custom Python scripts and tooling for specific forensic challenges. From automated log correlation to custom artifact parsers for proprietary formats.

Python forensics librariesElasticsearch for analysisCustom artifact parsers

When to engage Digital Forensics?

Incident Response

  • Ransomware attack - need for attribution
  • Data breach - extent determination
  • Insider threat - evidence collection
  • Fraud investigation - financial forensics

Proactive Forensics

  • M&A due diligence - IT asset verification
  • Compliance audits - data handling verification
  • Employee exit - sensitive data checks
  • Legal disputes - evidence preservation

Every byte tells a story

Digital evidence disappears quickly. RAM is overwritten, logs rotate, timestamps change. The sooner we start, the more complete the story.

Transparent forensic services

Incident Response

€275/hour

24/7 availability, 4-hour minimum

Forensic investigation

€225/hour

Planned investigations, detailed reporting

Expert witness

€350/hour

Court testimony & legal support

What is included?

Write-blocked evidence acquisition
Chain of custody documentation
Technical & executive reporting
30-day evidence retention

Digital Evidence. Legal Certainty.

From volatile memory to deleted files, from network traffic to cloud artifacts - we reconstruct the digital truth. Court-admissible, technically sound, business-focused.

24/7 Forensics hotline

+31 20 716 5487

Direct contact with certified forensic investigator