Log Analysis & Forensic Review
Hands-on review of security logs to answer the questions your SIEM can't
What this engagement covers
The service
Targeted, analyst-driven review of your log data - incident triage, compromise assessments, audit support, or just "what happened last Tuesday at 2am?"
What we test
Any log source you have - endpoint, identity, network, cloud, SaaS audit logs, email gateways, WAF, DNS. We query, correlate, and deliver a narrative.
How we run it
Scoped engagement with a defined question. We ingest the relevant logs, run analyst-driven queries, build a timeline, and hand back a written narrative plus the queries so you can re-run them yourself.
Scope definition and log source identification
Data ingest and normalization
Analyst-driven querying and pivoting
Timeline construction
Findings write-up and delivery
What you receive
Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.
- Written narrative answering the scoped question
- Reusable queries and dashboards
- Timeline of relevant events
- Indicators of compromise if found
- Recommendations for future monitoring
What we usually find
The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.
Who this is for
Findings are mapped to SOC 2, HIPAA, PCI-DSS, GDPR, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.
Scope it in one call
Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.