Skip to content
Digital Forensics & IR

Digital forensics and incident response across a 1,100-employee enterprise

A defensible account of what happened, how far it reached, and what to change — evidence handled to a standard that holds up outside the IT department.

Preserved under chain of custody.Correlated into one timeline.Swept across the whole estate.

EvidenceChain of custodyAcquired before remediation
Timeline reconstructionone sequence
  1. DiskArtefacts recovered
  2. MemoryMechanism and persistence
  3. LogsAuth · endpoint · network
  4. IOCIndicators recovered
Estate-wide IOC sweep
1,100+Employees in scopeEstate-wide indicator sweep
Client
Confidential enterprise groupIdentity withheld by agreement
Industry
Enterprise
Region
Saudi Arabia
Year
2025
What we did
Forensic investigation & incident responseCybersecurity service
The problem

When something goes wrong, the first casualty is certainty.

Forensic investigation and incident response across the estate of a Saudi enterprise group with more than 1,100 employees.

  1. 01 Certainty

    When something goes wrong on a network of this size, the first casualty is certainty. Logs disagree, people remember events differently, and the pressure to restore service immediately competes directly with the need to preserve what actually happened.

  2. 02 Scope

    Scope is the hard question. Establishing whether an incident touched one machine or four hundred, and whether anything left the organisation, cannot be answered by inspecting the obvious endpoint — it requires sweeping an estate of over 1,100 employees for the same indicators.

  3. 03 Scrutiny

    And the findings had to survive scrutiny. An internal summary is not sufficient where legal, regulatory or HR consequences may follow; the evidence has to be acquired and handled so that its integrity can be demonstrated later.

01 Preserve

Preserve before anything else.

Forensically sound acquisition of the affected systems with documented chain of custody, taken before remediation begins. Restoring a machine first destroys the answer to what happened on it.

Restore first

The machine works again — and the answer to what happened on it is gone.

Preserve first

Acquired, fingerprinted and logged. Then remediation can begin.

  • Forensically sound acquisition and documented chain of custody across affected systems.
Chain of custody logEX-01 · Disk imageSource: WS-0417
Illustrative
  1. AcquiredDay 1 · 03:10
    Forensic responder

    Forensically sound acquisition, before any remediation. Digest computed at source.

  2. Sealed and labelledDay 1 · 03:24
    Forensic responder

    Sealed; tag number recorded against the exhibit.

  3. Awaiting handover 3
  4. Awaiting handover 4
  5. Awaiting handover 5
02 Reconstruct

One sequence, not a set of disagreeing accounts.

Disk and memory artefacts correlated against authentication, endpoint and network logs to build a single defensible sequence of events, rather than a set of disagreeing partial accounts.

Logs on their own tell you that something happened. Disk and memory tell you how — and what stayed behind. Try it: start from the logs and add each source.

  • Disk, memory and mobile device forensic analysis.
  • Log correlation and full timeline reconstruction of the incident.
  • Malware and artefact analysis to establish mechanism and persistence.
Incident timeline · all times UTCA partial account4 of 8 events · 3 of 5 questions answered
Illustrative
  • How it started — answered
  • Mechanism — unknown
  • Persistence — unknown
  • Anything leave? — answered
  • Where it went next — answered
  1. 01:52
    logs · authWS-0417

    Valid account signs in from an unfamiliar internal host

  2. 01:58Unexplained — 4 events no enabled source can see
  3. 02:11
    logs · endpointWS-0417

    Endpoint protection reported disabled

  4. 02:26
    logs · networkWS-0417

    Sustained outbound transfer to the same address

  5. 02:40
    logs · authFS-02

    Same account signs in to a file server

Turn on IOCs to extract indicators for the sweep.
03 Scope

One machine, or four hundred?

Indicators recovered from the initial systems were swept across the wider environment covering all 1,100+ employees, to establish the true blast radius instead of assuming the first system found was the only one affected.

  • Estate-wide indicator sweep across an organisation of 1,100+ employees to determine scope.
Indicator sweep · 3 indicatorsScope assumed: one system
Illustrative

One system examined. Every other machine across the estate is not known to be clean — it simply has not been looked at.

04 Report

Report for the audience that matters.

Findings delivered in two registers — a technical account with the supporting evidence, and an executive summary stating what happened, what was affected, and what to do — suitable for legal, regulatory and HR use.

  • Root cause analysis with a prioritised remediation roadmap.
  • Expert reporting prepared to withstand legal and regulatory scrutiny.
Executive summary

Incident investigation report

Illustrative
What happened

An account was used to run an unauthorised program on one workstation, which set itself up to restart and then sent data to an outside address. The same account was then used on a file server.

What was affected

Five systems carry the same indicators, found by sweeping every employee's machine rather than assuming the first was the only one.

What to do, in order
  1. NowRemove the persistence and reset the account on every matched system.
  2. NextClose the root cause identified in the technical account.
  3. ThenKeep the indicators in monitoring so a return is seen, not assumed away.

Written for legal, regulatory and HR readers. Every statement points to the technical account.

How it fits together

From the first image taken to the report that stands up.

Evidence is acquired under chain of custody, analysed across disk, memory and log sources, correlated into a single timeline, then converted into indicators that are swept across the wider estate to establish scope before remediation and reporting.

  1. 01PreserveForensic acquisition
  2. 02PreserveChain of custody
  3. 03AnalyseDisk / memory analysis
  4. 04AnalyseLog correlation
  5. 05CorrelateTimeline reconstruction
  6. 06ScopeEstate-wide IOC sweep
  7. 07ResolveRoot cause & remediation
  8. 08ResolveExpert report
Disciplines
  • Digital Forensics
  • Incident Response
  • Memory Analysis
  • SIEM & Log Correlation
  • Threat Intelligence
  • Chain of Custody
Outcome

What changed.

1,100+
Employees in scope
Estate-wide indicator sweep

A single defensible timeline replacing conflicting partial accounts

True scope established across 1,100+ employees rather than assumed

Evidence handled so its integrity can be demonstrated later

Root cause identified with a prioritised remediation roadmap

Findings usable in legal, regulatory and HR proceedings

Next

Related work.

SCORA — Security assessments that end in proof, not a PDF
Flagship

SCORA

SCORAEnterpriseGlobal

Security assessments that end in proof, not a PDF

A security assessment and remediation platform: nine frameworks, every gap routed to an owner, evidence checked and read by AI, and an auditor-ready closure record — in English and Arabic.

Next.jsTypeScriptPostgreSQL
Read case studySee SCORA live
Nexus — The business card that never goes out of date
Flagship

Nexus

NexusEnterpriseGlobal

The business card that never goes out of date

An NFC and digital business card platform that runs a whole company's cards from one console, in five languages, across the UK, Europe and the Gulf.

Next.js 16React 19TypeScript
Read case studySee Nexus live
Sharebius Messenger — End-to-end encrypted messenger with integrated payments

Sharebius Messenger

SharebiusCommunicationsGlobal

End-to-end encrypted messenger with integrated payments

Privacy-first messaging with self-destructing messages, encrypted calls and built-in cryptocurrency payments.

JavaKotlinSwift
Read case study