Triage and scoping
Establishing what is confirmed, what is suspected, and what is still unknown, then determining whether the activity is ongoing. This drives every decision that follows, including whether containment can wait for more evidence.
The first hours of an incident are usually spent guessing. What was reached, whether it is still happening, whether to pull the plug. We work from artefacts rather than assumptions, and the first thing we establish is scope: what an attacker actually touched, and what they did not.
Preserve rather than clean. Do not reimage the affected machines, do not delete suspicious files, and do not rotate every credential yet. Those actions destroy the evidence that tells you how far this went. Isolate the affected hosts from the network, keep them powered on, and write down what you have already changed.
Email contact@lahavsec.com with what you are seeing and when it started. You will get a direct answer on whether this needs a full engagement, and if it does, we agree scope and start with evidence collection rather than paperwork.
We do not promise a response clock we cannot meet. Timelines depend entirely on the scope of the incident and the depth of investigation required, and you will get a realistic assessment during the first conversation rather than a number designed to win the engagement.
Scoped to the incident. A single compromised endpoint and a suspected domain-wide intrusion are very different engagements.
Establishing what is confirmed, what is suspected, and what is still unknown, then determining whether the activity is ongoing. This drives every decision that follows, including whether containment can wait for more evidence.
Filesystem and registry artefacts, execution evidence, persistence mechanisms, scheduled tasks and services, memory analysis where it is warranted, and anti-forensic activity where it is present.
Authentication and directory logs, EDR and endpoint telemetry, network and proxy records, and cloud audit trails, correlated into a timeline rather than reviewed in isolation.
How they got in, which credentials were used, where they went next, and which accounts and systems are implicated. Blind credential rotation without this is expensive and frequently misses the account that matters.
Indicators derived from your incident rather than from a generic feed, then hunted across the rest of the estate to find activity you had not yet noticed.
Practical support through containment and recovery, followed by remediation aimed at the root cause and detection content so the same path is visible if it is attempted again.
The same disciplined sequence on every engagement, so you know what is happening and when, and so nothing reaches your report unproven.
A conversation, not a form. We agree the boundary, the accounts, the timing and the escalation contact, and it is enforced technically.
We build the real picture of what is reachable, which is almost always larger than the inventory you were given.
Every candidate finding is actively validated against a baseline. Anything that fails is demoted or dropped before it reaches you.
Confirmed findings are linked into the routes an attacker would walk. One finding is a ticket. A path is a breach.
Evidence, reproduction steps, prioritised remediation and detection content, as SARIF, JSON and HTML mapped to MITRE ATT&CK.
You fix, we verify, and the report is updated. A finding is not closed because someone said it was.
We do not publish a fixed response time, because committing to one before knowing the incident would be dishonest. Timelines depend on the scope of the compromise and the depth of investigation required. Get in touch with what you are seeing and you will get a realistic assessment quickly, including whether another provider is a better fit for the urgency involved.
Preserve evidence. Isolate affected systems from the network but leave them powered on, stop deleting or cleaning anything, and note every change already made, including reboots and reimages. Volatile evidence disappears on shutdown, and reimaging removes the only record of how the attacker got in.
We are not lawyers and we will not advise you on notification obligations. We produce the technical findings and timeline your legal counsel, insurer and regulator need, in a form suitable for that audience, and we work alongside counsel where they are already engaged.
Sometimes, but expect less. Logs, backups, cloud audit trails and network records often survive endpoint reimaging and can still establish scope. We will tell you honestly what can and cannot be determined from what remains rather than billing for an investigation that cannot reach a conclusion.
A timeline of what happened, the scope of the compromise, indicators extracted from your environment, the root cause, and prioritised remediation with detection content. Written for two audiences: your engineers, and the people who have to make decisions about it.
Tell us what you are protecting and what worries you. You will get an honest answer on whether this engagement is the right next step, who would run it, and what it would cost, before you commit to anything.
אתר LahavSec פועל להנגשת השירותים והתכנים המוצגים בו לאנשים עם מוגבלות, בהתאם לתקנות שוויון זכויות לאנשים עם מוגבלות (התאמות נגישות לשירות), התשע"ג-2013, ותקן ישראלי 5568 המבוסס על הנחיות WCAG 2.0 ברמה AA.
באתר הוטמע תפריט נגישות המאפשר, בין היתר: הגדלה והקטנה של גודל הטקסט, מצב ניגודיות גבוהה, הדגשת קישורים, מעבר לגופן קריא, ריווח שורות מוגדל, סמן עכבר מוגדל, עצירת אנימציות והקראת העמוד.
חרף מאמצינו להנגיש את כלל הדפים באתר, ייתכן שיתגלו חלקים שטרם הונגשו במלואם. אנו ממשיכים לפעול לשיפור נגישות האתר באופן שוטף.
נתקלתם בבעיית נגישות? נשמח שתפנו אלינו לרכז הנגישות מטעם החברה בכתובת contact@lahavsec.com, ואנו נשתדל להשיב ולטפל בפנייה בהקדם האפשרי.
This site includes an accessibility menu (text size, contrast, underline links, readable font, line spacing, large cursor, stop animations, read‑aloud) per Israeli accessibility regulations (IS 5568 / WCAG 2.0 AA). For accessibility issues, contact .
הצהרת נגישות זו עודכנה לאחרונה בתאריך: 16/07/2026.