All Services

Digital Forensics & Breach Investigation

You know something happened. What you do not know is how far it went, what they took, how long they were in, and whether they are still there. That is the question digital forensics answers.

Computer and network forensics for businesses in Dallas, Fort Worth, Arlington and across the DFW metroplex. On-site when it matters, remote when speed matters more.

If You Think You Have Been Breached, Read This First

The most common thing that destroys a forensic investigation is the well-meaning cleanup that happens before anyone calls us. Wiping and reimaging the machine, deleting the suspicious account, restoring from backup, or simply rebooting can erase the only record of what actually happened.

  • Do not wipe or reimage the affected machines.
  • Do not power them off if you can avoid it — memory holds evidence that disappears on shutdown. Disconnect the network cable instead.
  • Do not delete the attacker's account or change the passwords they used until the access path is mapped.
  • Do preserve logs now. Firewall, VPN, email and server logs often roll over in 30 to 90 days, and sometimes in 7.
  • Do write down a timeline of who noticed what and when, before memories blur.

If you are mid-incident and need containment before investigation, start at incident response — that is the emergency service. Forensics is what tells you the full story afterwards.

The Questions a Forensic Investigation Answers

Containment stops the bleeding. It does not tell you what you are legally obligated to report, what your insurer needs, or which hole to actually close. These are the questions that decide all three.

How did they get in?

The initial access vector — a phished credential, an unpatched VPN appliance, an exposed remote access tool, a compromised vendor. Until this is known, the same door is still open.

How long were they inside?

Dwell time. The gap between first access and detection is routinely measured in weeks or months, and it changes the scope of everything else in the investigation.

Where did they go once inside?

Lateral movement. Which accounts were used, which systems were reached, and whether they got to the domain controller, the file server, or the backups.

Was data actually taken?

Access is not the same as exfiltration, and the difference decides whether you have a notification obligation. We look for the outbound transfer itself, not just the opportunity.

Whose data, and how much?

Notification duties under Texas law and under HIPAA turn on whose records were involved. A defensible record count is the difference between a targeted notice and a blanket one.

Are they still in there?

Persistence. Scheduled tasks, new service accounts, rogue mail rules, web shells and modified startup items are how an attacker returns a fortnight after you declared the incident closed.

What We Examine

A real investigation pulls from several independent sources, because any single one can be incomplete or deliberately tampered with. Where two sources disagree, that disagreement is itself a finding.

  • Disk images — forensically sound copies taken so the original is never worked on directly.
  • Memory captures — running processes, injected code and credentials in memory, which vanish at shutdown.
  • Windows event and security logs — logon types, account creation, privilege use and log-clearing events.
  • Firewall, VPN and network flow data — the outbound transfers that prove or disprove exfiltration.
  • Microsoft 365 and cloud audit logs — mailbox rules, delegated access, impossible-travel sign-ins and mass downloads.
  • Endpoint telemetry and EDR history — process ancestry showing what launched what.
  • Backup and shadow copy state — whether the attacker reached your recovery capability before encrypting.

What You Receive

  • An attack timeline — first access to detection, with the evidence behind each step.
  • A scope determination — which systems and which records, stated with the confidence level the evidence supports.
  • A root cause finding — the specific gap that allowed entry, not a generic list of best practices.
  • A prioritised remediation plan — what to fix first, and what can wait until next quarter.
  • Documentation your insurer and counsel can use — structured to the evidentiary standard carriers expect.

Reports are written to be read by two audiences: the technical person who has to implement the fix, and the owner or board member who has to make a decision about it.

What Forensics Can and Cannot Tell You

Any firm that promises certainty on every question is overselling. Being straight about the limits up front is part of the job, because your notification decisions and your insurance claim depend on knowing which findings are solid.

Usually answerable

  • The initial access vector
  • Which accounts were used and abused
  • Which systems were reached
  • Whether persistence was established
  • Whether backups were targeted
  • A defensible earliest-known-access date

Often harder, and why

  • Exactly which files were read — most systems do not log individual file access by default.
  • Precise exfiltration contents — encrypted outbound traffic shows volume and destination, not payload.
  • Activity beyond log retention — if logs rolled at 30 days and dwell time was 90, that window is gone.
  • Attribution — we can often identify tooling and behaviour patterns, rarely a named individual.

Where evidence is absent we say so and explain what would have preserved it, which is usually the most valuable part of the remediation plan. For the monitoring that produces that evidence next time, see our 24/7 managed SOC.

How Engagements Work

Emergency Investigation

A breach is confirmed or strongly suspected and you need scope fast — usually because a carrier, a regulator, a client or a deadline is waiting.

Evidence preservation begins immediately, often the same day. On-site across DFW when imaging requires it.

Post-Incident Review

The incident is contained and someone now has to explain what happened, to a board, an insurer, an auditor or a major customer.

Works from preserved evidence and existing logs. Produces the written record the business is being asked for.

Forensic Retainer

Pre-arranged terms so that when something happens there is no procurement delay while evidence ages out of your logs.

Pairs with an IR retainer, which carries a 2-hour guaranteed response.

On cost

Forensic investigations are scoped by the number of systems involved, the volume of logs, and how quickly you need the answer — not sold at a fixed per-seat rate. We will tell you the likely range on the first call, before you commit to anything, and we will tell you if we think the question can be answered more cheaply than a full investigation. Many cyber insurance policies cover forensic costs; if you have a policy, tell your carrier before you engage anyone, because most require it.

Digital Forensics Across Dallas-Fort Worth

We are headquartered in McKinney and work breach investigations across the metroplex — Dallas, Fort Worth, Arlington, Irving, Plano, Frisco and the mid-cities corridor in between. Disk imaging and evidence collection frequently require someone physically on site, which is why local matters for this service in a way it does not for monitoring.

North Texas businesses have had a direct lesson in why breach scope matters. When a major regional employer is hit, the organisations pulled into the fallout are usually not the initial target — they are the smaller suppliers, contractors and vendors connected through shared billing companies, IT providers and payroll processors. Those businesses discover months later that their data was inside someone else's breach. We wrote up what that pattern meant locally in our analysis of the JPS Health Network attack and its effect on Fort Worth businesses.

Related reading: how long attackers actually hide in a network, the first 60 minutes of a ransomware incident, and three contained attacks in Dallas, Plano and Frisco.

Frequently Asked Questions

What is the difference between incident response and digital forensics?

Incident response is the emergency service — it stops the attack, isolates affected systems and gets you operating again. Digital forensics is the investigation that establishes what actually happened: how they got in, how long they were there, where they went, and whether data left the building. They overlap, and on a live breach we do both, but they answer different questions. Containment protects the business today; forensics tells you what you must report, what to claim on insurance, and which specific gap to close so it does not happen again.

How do you determine how deep a breach went?

By reconstructing the attacker's path from independent evidence sources rather than from any single log. We image affected systems, capture memory where the machines are still running, and pull authentication records, firewall and VPN data, cloud audit logs and endpoint telemetry. Those sources are then correlated into a timeline: first access, privilege escalation, lateral movement, and any outbound transfer. Depth is established by what the evidence supports, and where it runs out — because logs rolled over or were cleared — we state that explicitly rather than assuming the best case.

Can you tell us whether data was actually stolen?

Often, yes, and it is usually the single most consequential finding because notification duties turn on it. We look for evidence of the transfer itself — outbound volume to attacker infrastructure, staging archives left behind, cloud download activity, mail forwarding rules. What is harder is naming exactly which files left when the traffic was encrypted, since that shows volume and destination but not contents. In that situation we tell you what the evidence does and does not establish, which is what your counsel needs in order to advise you properly.

What should we do right now, before you arrive?

Do not wipe, reimage or rebuild the affected machines, and avoid powering them off — memory holds evidence that disappears at shutdown, so disconnect the network cable instead. Do not delete the attacker's accounts yet. Preserve logs immediately, because firewall, VPN and email logs commonly roll over within 30 to 90 days and sometimes within 7. Write down a timeline of who noticed what and when. If you carry cyber insurance, notify your carrier before engaging anyone, as most policies require it. Then call us on 512-518-4408.

How much does a digital forensics investigation cost?

Cost is driven by the number of systems in scope, the volume of logs to process, and how fast you need the answer, so it is scoped per engagement rather than sold at a flat rate. We give you a likely range on the first call before you commit, and we will say so if we think your question can be answered without a full investigation. Many cyber insurance policies cover forensic costs, and panel counsel arrangements sometimes shape who you are permitted to engage — worth checking your policy before you sign anything.

Do you provide computer forensics in Fort Worth and Arlington?

Yes. We work breach investigations across the DFW metroplex from our McKinney headquarters, including Fort Worth, Arlington, Irving, Grand Prairie and the mid-cities. Forensics is one of the services where being local genuinely matters, because disk imaging and evidence collection often require someone physically present with the hardware. Remote collection is possible for cloud and endpoint evidence, and we start that immediately while arranging on-site work.

Will your report hold up for our insurer or for a regulator?

Our forensic reports are structured to meet the evidentiary standard cyber carriers expect, and we coordinate directly with your carrier and their panel counsel from the start of the engagement. Findings are stated with the confidence the evidence supports and separated clearly from inference, because a report that overstates certainty is worse than useless when it is challenged. Where an engagement is likely to end in litigation or a regulatory examination, tell us at the outset so evidence handling is documented accordingly from the first image.

How long does an investigation take?

Evidence preservation starts immediately, often the same day, and that is the time-critical part. A focused investigation into a single compromised mailbox or endpoint commonly produces findings within a few days. A multi-system intrusion involving lateral movement and a possible exfiltration question typically runs one to three weeks depending on log volume. If you are working to a regulatory clock — 72 hours for certain defence contract reporting, for example — tell us on the first call and we will scope to produce the required determination within that window.

Find Out How Far It Actually Went

If you suspect a breach, the evidence is decaying while you decide. Preserve it first, investigate second. We will tell you on the first call whether you need a full investigation or something smaller.