IT Forensics

Secure evidence and bring clarity after an incident.

IT forensics explains the cause to you.

After social engineering, digital sabotage or a ransomware attack, uncertainty often remains: What happened and what triggered it? Which data was leaked?
IT forensics from aramido answers these questions. We examine the situation thoroughly, establish the cause and explain the extent to you.
aramido brings clarity:
  • Court-ready evidence preservation
  • Precise root-cause analysis
  • Traceable evaluation
Carry out IT forensics now

Assumptions are not enough: facts instead of questions!

After an incident, digital traces are fleeting: careless access can delete information, and log files overwrite themselves. Once the data is gone, it can no longer provide any answers.

aramido therefore acts deliberately and quickly and examines precisely the systems that shed light on the cause. Using a proven approach, we secure the traces before they disappear.

Fast evidence preservation

Fast evidence preservation

Every minute counts. We respond at short notice, secure the volatile traces first and thereby give you the best possible result.

Clarity about the cause

Clarity about the cause

After an incident, countless questions arise. We examine the facts and answer what the cause was. In doing so, we create the basis for the next steps.

Enforceable results

Enforceable results

Our evidence chain meets the requirements of courts and insurers. You can therefore assert claims and clarify responsibilities.

How IT forensics works

IT forensics clarifies, after a security incident, what happened and how it came about. We reconstruct the course of events on the basis of digital traces left on systems, in networks and in the cloud, and turn them into a demonstrable basis for your next steps, such as an official notification, an insurance claim or a decision on further measures.

Cyber insurers, supervisory authorities and courts require documented and law-compliant processing. IT forensics is therefore usually no longer a purely internal matter today. Our results meet these requirements and support you with statutory reporting obligations, for example under GDPR, NIS-2 or DORA.

Findings only count if they hold up. That is why we work methodically: a documented chain of custody, hardware-supported acquisition and verifiable analysis steps ensure that the results are court-ready and usable for insurers and operational decisions.

DORA NIS-2 Critical Infrastructure GDPR ISO 27001
  • 1
    We clarify which data sources matter and secure them in the right order in accordance with the order of volatility. We also clarify the legal framework so that the results remain usable later.
  • 2
    We create copies of the storage media without altering the original data and secure them with checksums. The chain of custody thus remains verifiable at all times.
  • 3
    We evaluate the secured data and place the individual traces in a timeline. In this way we reconstruct what happened and what the cause was.
  • 4

    We produce an expert report that records all steps in a traceable manner, plus an understandable summary for decision-makers, legal advisers and insurers.

    The results form the basis for your next steps, such as an official notification or measures that prevent another IT incident.

Specialized forensics for every threat situation

The threat situation determines the forensic approach. Depending on the security incident, we reconstruct digital traces from a wide range of sources, from persistent data and volatile artifacts to complex network flows.

We use specialized methods to enable analysis across all levels. aramido looks precisely where the decisive clues lie.

Memory Forensics

Memory Forensics

Securing volatile data to reconstruct processes and uncover active attacks.

Disk Forensics

Disk Forensics

Examining storage media and forensic images to reconstruct data and traces of use.

Network Forensics

Network Forensics

Analyzing traffic to prove communication between compromised endpoints and data exfiltration.

Host Forensics

Host Forensics

Analyzing system and filesystem artifacts to trace user activity and the course of the attack.

Malware Forensics

Malware Forensics

Examining malicious software to identify attack patterns and prevent reinfection.

Cloud Forensics

Cloud Forensics

Clarifying incidents in a tenant's cloud environments across multiple regions.

Have evidence secured.

Briefly describe the situation in your message. We will get back to you promptly and take over the further preservation. Every minute counts so that no trace is lost.

Status

Please enable JavaScript to use the form.

Häufig gestellte Fragen

If a security incident is not clarified, it could happen again in the same or a similar way. It is therefore important to establish the cause. In addition, there are statutory reporting obligations to supervisory authorities, for example in the context of GDPR or NIS-2. Cyber-risk insurers also require professional processing before they grant coverage.
The chain of custody is the complete documentation of where evidence has been. It records precisely who had access to the original media, when and how, and how copies were created. Only through this transparency does the digital collection of evidence remain legally usable in court and the case traceable.
An initial triage to assess the situation usually takes place within a few hours. The detailed analysis varies greatly depending on the volume of data and the complexity of the case, and can take from a few days up to several weeks.
The costs depend heavily on the specific incident, the number of systems affected and the required analysis effort. In an initial conversation we identify the essential requirements and give you a transparent cost estimate.
Not necessarily. We distinguish between live forensics, where we secure volatile data while the system is running, and post-mortem forensics, where we analyze forensic copies in a controlled environment.
Most analyses can be carried out over secure remote access. In cases of physical manipulation or the acquisition of hardware, however, an on-site visit is often necessary to ensure the integrity of the evidence.
A backup only preserves the state of the data, not the system state at the time of the attack. Active network connections or the contents of working memory are not secured by a backup. Moreover, with modern attacks there is often a risk that the backups have already been compromised or encrypted.
While data recovery primarily aims to restore lost files, IT forensics focuses on evidentiary value. IT forensics uses its findings to explain the cause of a particular situation, for example patient zero, the point of first successful intrusion by a hacker group.
In many cases, yes. By analyzing slack space, journal files and memory dumps, we can often reconstruct fragments of deleted information, provided they have not yet been physically overwritten by new data.
We fundamentally distinguish between post-mortem analysis, the examination of isolated storage media after the incident, and live forensics, the acquisition of volatile data such as working memory, active processes and network connections while the incident is ongoing.

Your contribution to IT forensics

After an incident you want to act quickly and correctly. Especially in the first few minutes, it is decided whether traces are lost or can still be used later. That is why it is up to you to involve us early and leave your systems unchanged until they are secured.

With your knowledge of the systems and your infrastructure, together with our specialist expertise, we can carry out digital forensics as a team. We determine, in accordance with the order of volatility, which items need to be secured and in which order. Using your access, we create forensic copies and analyze the data.

  • Report the incident as early as possible
  • Leave affected systems in their original state
  • Name the systems you consider affected
  • Share your knowledge of your infrastructure with us