Services

The full scope of digital forensics — click a service to learn more

Computer and data-carrier analysis Forensic acquisition and full analysis of disks, flash drives and RAID arrays — preserving evidentiary value.

We create a bit-for-bit forensic image of the medium with checksum verification and perform the entire analysis solely on the copy — the original stays intact and is connected through a write blocker. We reconstruct user activity: opened files, history, connected devices, logs and artefacts on Windows, macOS and Linux.

We rebuild the timeline of events, recover deleted and hidden data, and document every action, building a chain of custody compliant with the ISO/IEC 27037 and 27042 standards.

Ask about this service →
Mobile device analysis Extraction and analysis of data from phones and tablets — including deleted content.

We acquire data from iOS and Android devices: SMS/MMS messages, calls, messenger data (WhatsApp, Signal, Messenger), location, photos and application data. Depending on the model and its security, we use logical, file-system or physical extraction.

Some data remains recoverable even after the user deletes it. Every extraction is performed preserving integrity and with full documentation, ready for use in legal proceedings.

Ask about this service →
Data recovery Recovery of deleted, formatted or damaged-media data.

We recover data lost through deletion, formatting, logical failure or physical damage to the medium. We work on a copy or in read-only mode so as not to deepen the data loss.

We carry out the process preserving evidentiary value — the recovered material can be used both in business and in proceedings. In difficult cases we rely on proven laboratory procedures.

Ask about this service →
Incident response (DFIR) Analysis of breaches, leaks and ransomware — attack vector, scope and event timeline.

Once an incident is detected, we secure volatile evidence (RAM, logs, system state) before it is overwritten. We establish the entry vector, the scope of the data breach, the attacker's actions and the full timeline of events.

We prepare a post-breach report together with indicators of compromise (IoC) and recommendations. We also support GDPR notification obligations and any subsequent proceedings.

Ask about this service →
Malware analysis Examining malware in isolation — behaviour, C2 communication and indicators of compromise.

We analyse malware samples in an isolated environment (sandbox), performing both static and dynamic analysis. We determine the malware's functions, persistence mechanisms, encryption and communication with C2 servers.

The result is a set of indicators of compromise (IoC) and a description of its operation — useful for cleaning up the infrastructure, detecting other infected systems and for evidentiary purposes.

Ask about this service →
Cloud forensics Securing and analysing evidence from cloud services and online accounts.

We acquire evidence from cloud services (Microsoft 365, Google Workspace, online drives, mail) and from accounts on internet services — respecting the legal basis for access. We analyse sign-in logs, user activity and change history.

The cloud increasingly stores key evidence. We secure it in a repeatable and documented way, establishing who accessed the data, when and from which device.

Ask about this service →
Cryptocurrency and blockchain analysis Tracing cryptocurrency transactions and analysing wallets for casework.

We trace the flow of funds across blockchain networks (Bitcoin, Ethereum and others), analyse addresses and wallets, and link transactions to entities and exchanges. We support cases involving fraud, money laundering and ransomware.

We prepare clear flow visualisations and descriptions ready for use in proceedings, indicating the points of contact with the real world (currency exchanges, trading platforms, services).

Ask about this service →
Open-source intelligence (OSINT) Gathering and analysing information from open sources.

We collect and analyse information from publicly available sources: registers, social media, websites and internet archives. We verify identities, capital and personal connections, and the reputation of entities.

We use this service in proceedings, employment cases, due diligence and asset tracing. Every finding is documented together with its source and date of acquisition.

Ask about this service →
Expert opinions and litigation support Court opinions and private expert reports — defensible at every stage of proceedings.

We prepare opinions commissioned by courts and prosecutors, as well as private expert reports for law firms and companies. Every opinion rests solely on verified facts and a repeatable methodology — another expert, repeating the steps, will obtain the same result.

We provide substantive support at every stage: from questions for the expert, through the analysis of an opposing opinion, to participation in procedural activities. We act impartially, preserving confidentiality and professional secrecy.

Ask about this service →

Pricing — free and individual

You pay for a specific scope, not a fixed price list. After a short consultation we give you the price and deadline in writing — before you decide.

Request a free quote →