Investigation and evidence

Cyber Forensic Audit

When an organisation suspects that an ex-employee retained access, that data left the building, or that internal systems were used in ways they should not have been, the first requirement is evidence that will stand up — not a theory. This engagement examines on-premises and cloud infrastructure, preserves evidence to legal standards, attributes activity to identity and time, and ends with both corrective actions and long-term prevention.

Security engineer's workstation with terminal output and a printed report
Delivery
25–35 working days
Platform modules
9 modules on one data model
Operated by
Webworx Asia, under a managed model

The situation

What this exists to fix

  • A departing employee may have retained access to systems, servers and email after exit.
  • There is suspicion of data exfiltration but no proof either way.
  • Logs exist but nobody has correlated them across authentication, file shares, mail and the network.
  • Any evidence gathered informally is already at risk of being inadmissible.
  • Off-boarding and access control gaps that allowed it are still open.
  • Management needs to decide on disciplinary or legal action and has nothing defensible to decide on.

The platform

9 modules, one data model.

Each module is purpose-built, and all of them share one record, one user directory and one audit trail.

01

Data acquisition

Non-intrusive imaging and cloning of drives, preserving timestamps, metadata and audit trails under a zero-alteration policy so evidence remains admissible.

02

Network forensics

Packet captures, traffic anomaly mapping, and VPN and firewall access log analysis.

03

Disk forensics

Sector-level imaging, file integrity reconstruction, deleted file recovery, and exfiltration and deletion analysis.

04

Memory forensics

RAM captures where possible, malware artefact hunting and credential harvesting indicators.

05

Log analysis

Authentication logs, file-share access patterns, database and administrative activity, and syslog or SIEM correlation across directory, cloud and endpoints.

06

Email forensics

Suspicious forwarding rules, unauthorised mailbox access, egress patterns across attachments, downloads and auto-sync, and Exchange, Microsoft 365 or Google Workspace audit trails.

07

Attribution and reporting

Correlation of activity to user identity and time, a timeline of events, findings mapped to systems, observed cleanup or obfuscation, and legally defensible audit documentation.

08

Remediation

Patch and policy recommendations, access control restructuring, network segmentation and least-privilege enforcement, and a cybersecurity policy overhaul covering the off-boarding failure that allowed it.

09

Compliance review

Verification against applicable standards — GDPR for data privacy and retention, HIPAA where healthcare data is involved, PCI-DSS where payments are processed.

What you receive

Deliverables

  • Comprehensive forensic audit report
  • Incident chronology and impact assessment
  • Evidence bundle, where permissible
  • Legal-ready documentation suitable for disciplinary action or litigation
  • Mitigation recommendations, both policy and technical
  • Security hardening roadmap
  • Optional post-remediation support plan

What changes

Outcomes

  • A defensible answer on whether unauthorised access or exfiltration occurred
  • Evidence preserved to a standard that supports disciplinary or legal action
  • Activity attributed to identity and time rather than inferred
  • The access control and off-boarding gaps closed
  • A hardening roadmap that reduces the chance of a repeat

How it is delivered

25–35 working days

The plan we quote, with the gates where you sign off before the next stage starts.

  1. 01

    2–3 days

    Requirement collection and environment access

    Scope, authorisation, credentials and physical access arranged.

  2. 02

    5–7 days

    Device and server imaging

    Forensic acquisition under a zero-alteration policy.

  3. 03

    10–15 days

    Forensic investigation, log and network audit

    Disk, memory, log, network and email analysis.

  4. 04

    5–7 days

    Correlation and threat attribution

    Activity mapped to identity and time.

  5. 05

    3–5 days

    Final report, remediation roadmap and briefing

    Findings presented to management with corrective and preventive actions.

Integrate, don't rebuild

Built on services that already work

We build and own the application, the workflows and the operations. For infrastructure we integrate proven managed services rather than untested in-house equivalents — lower deployment risk, faster launch, and infrastructure billed at real usage.

  • Active Directory
  • Microsoft 365
  • Google Workspace
  • SIEM platforms
  • Firewall and VPN logs
  • Cloud consoles

Questions

Asked before every engagement

No engagement can promise that, and you should distrust one that does. Across aggregated industry studies, properly conducted forensic audits detect unauthorised activity in roughly 62–71% of suspected cases, and evidence recovery averages 70–85% depending on log retention policy, whether files were deleted, and how devices were handled before they were secured. We use industry frameworks to maximise actionable findings, and we report honestly on what could not be established.

Encrypted drives may require key recovery. High log and storage volumes lengthen analysis. Data jurisdiction and privacy law must be respected. Insider activity frequently involves deliberate stealth. And we need access — credentials, physical presence and the implicated devices themselves. We work with your IT team to minimise disruption while maximising retrieval accuracy.

Direct access to on-premise servers, networking racks and restricted rooms; handover of the relevant devices; administrative access to servers, directory, cloud consoles, workstations, mail and collaboration systems, logs, SIEM, firewall and API endpoints; and an onsite escort for infrastructure access. Travel and accommodation for the team where the engagement is onsite.

No. A penetration test asks whether someone could get in. A forensic audit asks whether someone already did, what they took, and whether it can be proven. If you want the first, that is a separate engagement.

More platforms

Other solutions

Start with the problem, not the product

Tell us what is breaking. We will scope it honestly — including telling you when Cyber Forensic Audit is more platform than you need.