PikoSystem IT engineering services
Security & Recovery

Security incident investigation and digital forensics

Cleaning a hacked server fixes today's problem. Without knowing how the attacker got in, there's a good chance they come back. We preserve the evidence and analyse logs, disks and memory to establish the entry point, the timeline and what the attacker did.

Tools & technology digital-forensics
  • Autopsy
  • Volatility
  • KAPE
  • Velociraptor
  • FTK Imager
  • Plaso
  • Sysmon
  • Wazuh
5work areas
4deliverables
4steps

What is Digital Forensics?

Digital forensics is the preservation and analysis of log, disk and memory evidence after a security incident, to establish how an attacker got in, when it happened and what they did. It is needed when a server that was cleaned gets infected again, customer data turns up somewhere public, or management or a lawyer asks for a documented incident report. PikoSystem takes disk and memory images with recorded hashes and chain of custody, reviews login, web server and firewall logs, Windows event logs and Linux auth.log to build a timeline, examines modified files, web shells and suspicious processes with Autopsy and Volatility, and searches other systems for backdoors and unknown SSH keys. You receive a technical report with evidence for each finding, a plain-language management summary, a list of indicators of compromise and prioritized remediation steps.

When you need Digital Forensics

  • Our server was hacked, we cleaned it, and it got infected again.
  • An admin account logged in at a time when nobody was working.
  • Customer data was published somewhere and we don't know how it leaked.
  • Management or our lawyer wants a documented incident report.

What Digital Forensics includes

01

Evidence collection

Disk and memory images taken with standard tools, hashes recorded, and chain of custody documented.

02

Log analysis

Login, web server and firewall logs, Windows event logs and Linux auth.log reviewed to build an incident timeline.

03

Disk and memory analysis

Modified files, web shells, scheduled tasks, suspicious services and in-memory processes examined with Autopsy and Volatility.

04

Root cause

The exploited vulnerability or compromised account identified, along with the attacker's movement through the network and the data they could reach.

05

Threat hunting

Other systems searched for backdoors, added users and unknown SSH keys.

What you get from Digital Forensics

  • A technical report with the incident timeline and evidence for each finding
  • A plain-language management summary
  • A list of indicators of compromise (IOCs) for future monitoring
  • Remediation actions in order of priority

Digital Forensics: a practical guide

Incident response steps: where does forensics fit?

The widely used NIST SP 800-61 model describes incident response in four phases: preparation; detection and analysis; containment, eradication and recovery; and post-incident activity. Forensics sits mainly in analysis, yet it shapes every later phase. Without knowing the scope of the intrusion, containment and cleanup stay partial.

Order of work matters for the same reason. Volatile evidence such as memory contents, open network connections and running processes disappears at shutdown and has to be collected before disk imaging. If a server was reinstalled before anyone called us, some questions can no longer be answered with proof.

Which Windows event IDs matter in an investigation?

In the Security log, 4624 is a successful logon and 4625 a failed one, and the logon type, 10 for RDP, shows how the session arrived. 4672 marks a logon with special privileges, 4720 a new user account and 4698 a new scheduled task. Event 1102 means the Security log was cleared.

In the System log, 7045 records a newly installed service, a trace left by tools like PsExec. The TerminalServices-RemoteConnectionManager log records RDP authentication as event 1149, and PowerShell event 4104 captures script text when Script Block Logging is enabled. On Linux, auth.log or secure, the output of last and lastb, and users' shell history are the starting points.

Why hacked server logs often fall short

In many investigations the log that should hold the answer doesn't exist. The Windows Security log is small by default and overwrites itself within days on a busy server. Process creation auditing (event 4688) and Script Block Logging are off by default, and servers whose clocks aren't synced with NTP make timelines hard to build.

Preparation fixes this: larger log sizes, a sensible audit policy, Sysmon, logs shipped to a separate server the attacker can't wipe, and consistent time across every system. With those settings in place, the next investigation starts from evidence.

What determines the scope of a forensic investigation?

The number of systems involved matters, and the condition of the evidence matters more. A machine that is still running, with memory available to capture, answers far more questions than a server restored or reinstalled after the incident.

Other factors: how long logs are kept and whether central logging exists, disk encryption with BitLocker or LUKS and access to recovery keys, cooperation from the data center or hosting provider, disk sizes, and whether the report is for internal use or legal proceedings, which demand stricter chain of custody documentation.

How Digital Forensics works

  1. 01

    Call and preserve

    We tell you what not to touch and collect evidence before any cleanup.

  2. 02

    Analysis

    We examine logs, disk and memory images and rebuild the incident timeline.

  3. 03

    Report findings

    We deliver the technical report and management summary and walk you through the findings.

  4. 04

    Remediate and follow up

    We close the entry point or help your team close it, and add the IOCs to your monitoring.

Digital Forensics: frequently asked questions

Our server was hacked. What should we do first?

Disconnect the server from the network, but avoid shutting it down or reinstalling it if you can. Don't delete logs or suspicious files, and write down everything that has been done so far. Then call us so we can collect evidence before anything else changes.

Can your forensic report be used in legal proceedings?

We collect and report evidence using standard methods, recorded hashes and chain of custody. Whether it is accepted is up to the court or authority, and an officially appointed expert may also be required. If legal action is likely, tell us at the start.

Do you investigate attack logs on WordPress sites?

Yes. We review web server access logs, control panel logs and changes to WordPress files and the database to find whether the breach came from a plugin, a theme or a weak password. Site cleanup is available if needed.

Related searches

  • digital forensics
  • hacked server investigation
  • security incident analysis
  • incident response
  • breach root cause analysis
  • attack log analysis

Quote

Tell us what you need, we'll come back with a plan and a price

A few lines on where things stand and what you want is enough. An engineer calls you back, not a sales rep.

  1. 01We read your request and call if anything is unclear.
  2. 02If needed, we do a quick remote review or a site visit.
  3. 03You get a written proposal with scope, timeline and cost.

Your details are only used to answer this request.