Has a breach occurred?
Investigate signs of compromise and data movement.
NetSecurity Forensic Labs
Every trace tells a story.
Computer forensic investigations, managed detection and response, data breach investigations, malware analysis and incident response. Licensed and certified investigators, a secure lab and processes that withstand legal scrutiny.

01 Digital & cyber forensics center of excellence
Complex questions. Disciplined investigation.
A secure, state-of-the-art facility for high-profile investigations and for research and development in endpoint security, staffed by forensic practitioners, security researchers and software developers.
Technical depth and a well-defined quality assurance program support investigations designed to withstand legal scrutiny. Our work spans computer architecture, operating-system internals, networks, cloud platforms and storage systems.
Malware research, product testing, forensic and anti-forensic techniques, emerging tools, security trends and attacker tactics, techniques and procedures inform our work.
That research produced our flagship innovation, the ThreatResponder® Platform, and its Malyzer™ module for malware analysts and forensic investigators.
Meet NetSecurity Forensic Labs02 Managed service
The investigation can start before the incident does.
Around-the-clock visibility into the threats facing your endpoints, from nation-state adversaries and hackers to insiders quietly taking confidential information or intellectual property.
Powered by ThreatResponder, our team connects endpoint activity with threat-intelligence enrichment to identify attacker behavior, respond to threats and guide proactive risk mitigation.
Discuss managed detection
Recognize sophisticated attacks and covert activity.
Neutralize threats in any phase of the attack lifecycle.
Mature your security program and stay compliant.
03 Investigation service
Reconstruct the activity. Reveal the evidence.
Were your systems used for criminal, unauthorized civil or policy-violating activity? We establish what was accessed, copied, changed or deleted, and whether an intruder was involved.
Scope the investigation and acquire the data with forensic methods, documenting how it is handled.
Examine system and application artifacts; recover deleted, hidden and encrypted files on Windows, macOS and Linux.
Correlate system usage, communications and network activity to establish what happened to the data.
Report the findings and what they mean, supported by documented methods that stand up to legal scrutiny.

03 Scope of an investigation
Across devices. Across networks. Across the cloud.
We recover and analyze evidence from desktops, servers, network and mobile devices, IoT and embedded systems, cloud platforms and removable media, in a wide variety of formats. The question you need answered sets the scope.
OnWindows · macOS · Linux · embedded systems
04 Investigation service
Suspicion is a signal. Evidence is the answer.
Suspect a compromise? Establish what happened, identify affected systems and understand the exposure.
Instead of mobilizing a brigade of incident responders, we deploy ThreatResponder agents to suspect systems or across the enterprise, and begin detecting breach and exfiltration activity within minutes. Our team helps detect threat actors, disrupt attacker infrastructure, evict adversaries and reduce the risk of another incident.
Investigate signs of compromise and data movement.
Determine scope and support containment and response.
Recommend ways to reduce the attack surface and prevent recurrence.
High-profile investigations for retail, gaming, technology, government and corporate environments.
Discuss a suspected breach05 Analysis service
Take the threat apart. Understand what it can do.
Our developers, researchers and investigators have conducted thousands of computer investigations, some involving malicious software, others malware-less techniques. Five complementary techniques reveal what a sample can do, the risk it carries and how to mitigate it.

Inspect the sample without running it: file structure, metadata and embedded indicators.
Never executedRun it in a controlled environment and observe process activity, system changes and network behavior.
Executed in isolationExamine program logic and functions to understand the actions the software can perform.
Logic & functionsWork back from the executable to uncover mechanisms, hidden functionality and evasion techniques.
Hidden functionalityConnect the findings with known indicators and adversary techniques to add context and guide mitigation.
Indicators & techniquesExpert analysis, platform-assisted. ThreatResponder® and its Malyzer™ module support our analysts with threat intelligence, machine learning and behavior rules. Experienced practitioners interpret the results.
Speak with a malware analyst06 Response & readiness
Ready before. Decisive during. Stronger after.
Reduce business interruption with a response grounded in evidence.
Our experienced responders help evaluate, escalate, mitigate and contain incidents, from securing systems and networks to acquiring data and analyzing evidence. ThreatResponder automates collection, threat analytics and detection to support the investigation.
Create, implement and roll out incident response policies, processes and capabilities. Prepare your organization to manage cyber incidents as part of its wider crisis readiness.
Secure affected systems, forensically preserve data and investigate networks, operating systems, databases and other infrastructure to establish the extent of compromise.
Analyze the evidence to understand the actors and activity involved. Use the findings to improve response and help prevent future occurrences.
A clearer account of the incident.
Start with the right questions
Tell us what you need to understand. Our team can discuss the appropriate investigation, analysis or response service for your situation.