Skip to main content
Home/Services/Digital Forensics
Security Testing

Digital Forensics

Evidence-grade forensic analysis for incidents, HR, and litigation

HIPAA PCI-DSS SOX GDPR SOC 2
engagement log Digital Forensics testing
day 01scopetargets confirmed · rules of engagement signedagreed
day 01reconattack surface mappedcomplete
day 02findingData theft prior to departurecritical
day 03findingUnauthorized access patternshigh
day 04triagereviewed and countersigned by a Lorikeet pentesterpublished
day 04delivertickets opened in your tracker201
afterretestfixes verified · included in scopeno charge
retest included human countersigned report your auditor accepts
2-6 weeks per engagementtypical duration $15,000fixed scope, from 6deliverables 6methodology stages
Scope

What this engagement covers

The service

Forensically sound collection and analysis of endpoints, servers, mobile devices, and cloud workloads - produced to a standard that holds up in litigation and regulatory proceedings.

What we test

Windows/macOS/Linux endpoints, mobile devices (iOS/Android), cloud instances, server images, and memory captures. Chain-of-custody documented throughout.

Method

How we run it

Established forensic protocols, industry-standard tooling (FTK, EnCase, Volatility, Axiom), and analyst examiners with law-enforcement and IR backgrounds. Reports produced in both executive and technical formats.

01

Evidence preservation and imaging

02

Chain-of-custody establishment

03

Artifact triage (filesystem, registry, memory)

04

Timeline reconstruction

05

Report production

06

Testimony and expert witness support

Deliverables

What you receive

Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.

  • Chain-of-custody documentation
  • Forensic image acquisition
  • Timeline of relevant activity
  • Artifact analysis report
  • Affidavit-ready findings when required
  • Expert witness availability
Typical results

What we usually find

The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.

Data theft prior to departure Unauthorized access patterns Deleted file recovery USB mass-storage evidence Cloud sync exfiltration Anti-forensics activity
Fit

Who this is for

Employee termination investigations
IP theft cases
Regulatory investigations
Litigation discovery support
Post-incident forensic review
Standards this supports

Findings are mapped to HIPAA, PCI-DSS, SOX, GDPR, SOC 2, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.

Next

Scope it in one call

Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!