Home  /  Services  /  Incident Response
Services · DFIR

Incident
response.

The first hours of an incident are usually spent guessing. What was reached, whether it is still happening, whether to pull the plug. We work from artefacts rather than assumptions, and the first thing we establish is scope: what an attacker actually touched, and what they did not.

01
If you are in an incident

If you are in one right now, start here.

01

Before you do anything else

Preserve rather than clean. Do not reimage the affected machines, do not delete suspicious files, and do not rotate every credential yet. Those actions destroy the evidence that tells you how far this went. Isolate the affected hosts from the network, keep them powered on, and write down what you have already changed.

02

Then get in touch

Email contact@lahavsec.com with what you are seeing and when it started. You will get a direct answer on whether this needs a full engagement, and if it does, we agree scope and start with evidence collection rather than paperwork.

03

What we do not do

We do not promise a response clock we cannot meet. Timelines depend entirely on the scope of the incident and the depth of investigation required, and you will get a realistic assessment during the first conversation rather than a number designed to win the engagement.

02
Coverage

What the investigation covers.

Scoped to the incident. A single compromised endpoint and a suspected domain-wide intrusion are very different engagements.

01

Triage and scoping

Establishing what is confirmed, what is suspected, and what is still unknown, then determining whether the activity is ongoing. This drives every decision that follows, including whether containment can wait for more evidence.

02

Endpoint and artefact analysis

Filesystem and registry artefacts, execution evidence, persistence mechanisms, scheduled tasks and services, memory analysis where it is warranted, and anti-forensic activity where it is present.

03

Log and telemetry analysis

Authentication and directory logs, EDR and endpoint telemetry, network and proxy records, and cloud audit trails, correlated into a timeline rather than reviewed in isolation.

04

Initial access and lateral movement

How they got in, which credentials were used, where they went next, and which accounts and systems are implicated. Blind credential rotation without this is expensive and frequently misses the account that matters.

05

IOC extraction and hunting

Indicators derived from your incident rather than from a generic feed, then hunted across the rest of the estate to find activity you had not yet noticed.

06

Containment, eradication and hardening

Practical support through containment and recovery, followed by remediation aimed at the root cause and detection content so the same path is visible if it is attempted again.

03
How the engagement runs

Six steps, every time.

The same disciplined sequence on every engagement, so you know what is happening and when, and so nothing reaches your report unproven.

01

Scope

A conversation, not a form. We agree the boundary, the accounts, the timing and the escalation contact, and it is enforced technically.

02

Map

We build the real picture of what is reachable, which is almost always larger than the inventory you were given.

03

Prove

Every candidate finding is actively validated against a baseline. Anything that fails is demoted or dropped before it reaches you.

04

Chain

Confirmed findings are linked into the routes an attacker would walk. One finding is a ticket. A path is a breach.

05

Report

Evidence, reproduction steps, prioritised remediation and detection content, as SARIF, JSON and HTML mapped to MITRE ATT&CK.

06

Retest

You fix, we verify, and the report is updated. A finding is not closed because someone said it was.

04
Straight answers

The questions we actually get.

How quickly can you respond?

We do not publish a fixed response time, because committing to one before knowing the incident would be dishonest. Timelines depend on the scope of the compromise and the depth of investigation required. Get in touch with what you are seeing and you will get a realistic assessment quickly, including whether another provider is a better fit for the urgency involved.

What should we do before we contact you?

Preserve evidence. Isolate affected systems from the network but leave them powered on, stop deleting or cleaning anything, and note every change already made, including reboots and reimages. Volatile evidence disappears on shutdown, and reimaging removes the only record of how the attacker got in.

Do you handle legal and regulatory reporting?

We are not lawyers and we will not advise you on notification obligations. We produce the technical findings and timeline your legal counsel, insurer and regulator need, in a form suitable for that audience, and we work alongside counsel where they are already engaged.

Can you help if we have already reimaged everything?

Sometimes, but expect less. Logs, backups, cloud audit trails and network records often survive endpoint reimaging and can still establish scope. We will tell you honestly what can and cannot be determined from what remains rather than billing for an investigation that cannot reach a conclusion.

What do we receive at the end?

A timeline of what happened, the scope of the compromise, indicators extracted from your environment, the root cause, and prioritised remediation with detection content. Written for two audiences: your engineers, and the people who have to make decisions about it.

Start here

Scoping is
a conversation.

Tell us what you are protecting and what worries you. You will get an honest answer on whether this engagement is the right next step, who would run it, and what it would cost, before you commit to anything.

Direct line contact@lahavsec.com
Offensive Security · Defensive Value
Accepting new engagements