Skip to main content

Cyber Forensics & Investigation

Email & Cloud Investigation

Business email compromise and cloud tenant investigations across Microsoft 365, Google Workspace and IaaS audit logs.

Every engagement includes manual validation, a two audience report and free re-testing.

Get a scoped quote+91 96682 00222

What this actually is

Business email compromise remains one of the most expensive attacks in India, and it rarely involves malware. Someone gets into a mailbox, watches for a while, and then intervenes in a payment conversation at exactly the right moment.

Investigating it means reading audit logs most organisations do not know they have. Mailbox rules, sign-in records, consent grants to third-party applications, and delegated access nobody remembers approving.

We investigate Microsoft 365, Google Workspace and cloud tenants, and we tell you what was accessed rather than what was possibly accessed.

What we go after

  • Mailbox audit log analysis
  • Sign-in and conditional access review
  • Malicious inbox rule and forwarding detection
  • OAuth application consent grant review
  • Delegated and shared mailbox access
  • Cloud tenant configuration change history
  • Data access and download determination
  • Persistence mechanism identification

How we run it

  1. 01

    Preserve

    First priority is evidence integrity. We image and hash before anyone starts changing things.

  2. 02

    Contain

    Stop the bleeding without destroying the trail. These two goals fight each other, and experience is what balances them.

  3. 03

    Investigate

    Timeline reconstruction across endpoint, network, cloud and identity, until we can say what happened and when.

  4. 04

    Report

    Findings written to survive scrutiny from a regulator, an insurer or a court.

  5. 05

    Harden

    The root cause fixed, not just the symptom, so the same door is not open next quarter.

What you receive

  • Compromise timeline with account-level detail
  • Data access assessment for notification decisions
  • Persistence mechanisms found and removed
  • Tenant hardening recommendations
  • Report suitable for regulator and insurer

Who needs this

Any organisation that has suffered or suspects a mailbox compromise, invoice fraud or unauthorised cloud tenant access.

How long it takes

Three days to two weeks.

Standards this satisfies

  • NIST SP 800-61
  • CERT-In
  • DPDP Act
  • ISO 27035

Why it matters

After an incident there are three questions that have to be answered, and none of them can be answered well without preparation: when did it start, what was actually taken, and is the attacker still inside. Regulators, insurers and customers all ask them, and vague answers are treated as bad ones.

The most common problem we meet is that the evidence is already gone. Systems rebuilt, logs rotated, machines rebooted in good faith before anything was preserved. How the first hour is handled decides whether the rest of the investigation is possible.

Choose how you want this delivered

Most of the price difference between quotes comes down to this one choice, and it is rarely explained. Pick one to see what it covers, what it suits and what it costs you.

Terms, contacts and access agreed in advance, with a guaranteed response time. The value is not the discount, it is that the first day is spent responding rather than negotiating a contract while an intruder is still active.

Choose this when

  • Any organisation holding regulated or personal data
  • Boards or insurers asking about incident readiness
  • You want the mobilisation clock to start in minutes, not days

Effort and cost

An annual fee, with unused hours typically usable for proactive work. The cheapest reduction in breach cost available.

Scope it yourself, before you call anyone

Answer a few questions and you get an indicative number, the working behind it and what your answers tell us. It runs in your browser, so nothing you type reaches us.

1/5

Roughly how many personal records do you hold?

What we look for, and keep finding

These are the classes of problem this work exists to surface. Not every engagement finds all of them, but these are the ones that turn up often enough to be worth naming.

  • Evidence destroyed by the response

    The most common problem we meet. Systems rebuilt, logs rotated, machines rebooted before anything was preserved. What could have been established is often gone before we arrive.

  • Incomplete timeline

    Knowing the breach happened but not when it began. Without an accurate first access, scope cannot be bounded and notification obligations cannot be answered honestly.

  • Unclear data exposure

    The question every regulator and customer asks: what was actually taken. Answering it needs artefacts that only exist if logging and retention were adequate beforehand.

  • Chain of custody failures

    Evidence handled in a way that will not survive challenge. If there is any prospect of proceedings, how the first hour was handled decides whether the findings are usable.

  • Persistence left behind

    Recovery declared complete while access remains. We look specifically for the second and third mechanism, because a competent intruder does not rely on one.

Who runs your engagement

Investigators who have given evidence

Investigations are led by people who have produced findings that survived challenge. Our founder advises law enforcement and has trained officers in cyber crime investigation, so the method is one that police and courts recognise.

Questions we get asked

We reset the password. Is that enough?

Almost never. Attackers commonly leave inbox rules, OAuth grants or delegated access that survive a password reset. Those need finding and removing individually.

How do we know whether data was actually taken?

That depends on your licensing and audit retention. We will tell you what the logs can and cannot prove, rather than guessing, because your notification obligations turn on it.

Ready to scope your email & cloud investigation?

Thirty minutes with a senior engineer, and you leave with a written scope and indicative effort.