Skip to content
Macksofy Technologies
24×7 IR hotline · 30-min bridge SLA

When the worst happens, every minute matters.

Macksofy's DFIR team responds to ransomware, business email compromise, insider threats and APT intrusions across India and the GCC. Court-admissible chain of custody, structured Velociraptor + KAPE collection, expert reporting for regulators, insurers and law enforcement.

30 min
bridge for retainer clients
2 h
bridge for new clients
24 h
team on-ground (India + UAE)
6 h
CERT-In incident format
In short

What is DFIR?

DFIR (Digital Forensics and Incident Response) is the discipline of containing a live cyberattack, investigating how it happened, and recovering safely — covering ransomware, business email compromise, and Active Directory compromise. Macksofy's GCFA/GREM/CHFI-certified team responds across India, preserves evidence, and files CERT-In incident reports.

Incident timeline

T+0 → T+7d. Every minute documented.

Anonymised composite from the typical Macksofy ransomware engagement — what happens at each clock-tick from the moment your CISO hits the hotline.

  • Contain incidents in hours, not weeks
  • Preserve evidence for legal / regulatory action
  • Satisfy CERT-In incident reporting requirements (6-hour rule)
  • Reduce insurance claim disputes via proper documentation
  1. Triage call

    T+0

    30-min bridge · scope · isolate · engagement letter

  2. Evidence collection

    T+2h

    Velociraptor agents · KAPE offline · cloud log preservation

  3. Live analysis

    T+8h

    Volatility 3 memory · Plaso timeline · IOC extraction

  4. Containment

    T+24h

    Attacker eviction · persistence removal · cred reset

  5. CERT-In report

    T+72h

    6-hour-rule compliant · insurance · legal-ready

  6. Recovery + lessons

    T+7d

    Hardening plan · detection upgrades · tabletop replay

Chain of custody

Evidence that survives court.

Every forensic artifact gets a SHA-256, a custodian signature and an encrypted storage chain — accepted by Indian courts, RBI investigations, CERT-In and cyber-insurance arbitrators.

Stage 01
Acquisition

FTK Imager · write-blocker · SHA-256 captured

Stage 02
Live capture

Volatility 3 memory · network state · open handles

Stage 03
Sealed evidence

Encrypted storage · access log · custodian signed

Stage 04
Examination

Air-gapped lab · Autopsy · Plaso timeline

Stage 05
Court-admissible

Chain log · expert testimony · CERT-In format

court-admissible since 2014· accepted by RBI · CERT-In · India courts
Engagement snapshot

Ransomware · BEC · insider threat.

Mid-size manufacturer (Maharashtra)

Ransomware (LockBit variant)

Root cause · Initial access via exposed RDP + leaked creds; lateral movement via PsExec

Containment in 11h; 80% of systems restored from backups within 72h

Risk severity · Critical
LMHC
Forensic toolchain

Volatility · Plaso. Real DFIR tools.

Tools we operate
VelociraptorKAPEVolatility 3Plaso / log2timelineAutopsyFTK ImagerX-Ways ForensicsSANS SIFT WorkstationREMnux (malware)MISP (IOC enrichment)
Investigation methodology

Every hour accounted for.

DFIR · Start
  1. Phase 01

    1 · Triage call

    • 30-minute bridge call to scope the incident
    • Initial containment guidance (network isolation, etc.)
    • Engagement letter + RoE for forensic work
    01
    Phase 01

    1 · Triage call

    • 30-minute bridge call to scope the incident
    • Initial containment guidance (network isolation, etc.)
    • Engagement letter + RoE for forensic work
  2. Phase 02

    2 · Evidence collection

    • Velociraptor agents deployed (or KAPE for offline)
    • Memory + disk imaging where required
    • Cloud log preservation (CloudTrail, Activity Log, Audit Log)
    02
    Phase 02

    2 · Evidence collection

    • Velociraptor agents deployed (or KAPE for offline)
    • Memory + disk imaging where required
    • Cloud log preservation (CloudTrail, Activity Log, Audit Log)
  3. Phase 03

    3 · Analysis

    • Timeline construction (Plaso / log2timeline)
    • Memory analysis (Volatility 3)
    • Malware triage + IOC extraction
    • Lateral movement reconstruction
    03
    Phase 03

    3 · Analysis

    • Timeline construction (Plaso / log2timeline)
    • Memory analysis (Volatility 3)
    • Malware triage + IOC extraction
    • Lateral movement reconstruction
  4. Phase 04

    4 · Containment + eradication

    • Attacker eviction plan
    • Persistence mechanism removal
    • Credential reset orchestration
    04
    Phase 04

    4 · Containment + eradication

    • Attacker eviction plan
    • Persistence mechanism removal
    • Credential reset orchestration
  5. Phase 05

    5 · Reporting

    • Executive incident summary
    • Technical forensic report
    • CERT-In incident report (6-hour rule compliance)
    • Insurance + legal-ready documentation
    05
    Phase 05

    5 · Reporting

    • Executive incident summary
    • Technical forensic report
    • CERT-In incident report (6-hour rule compliance)
    • Insurance + legal-ready documentation
  6. Phase 06

    6 · Recovery + lessons

    • Hardening recommendations
    • Detection improvements
    • Tabletop exercise replay (optional)
    06
    Phase 06

    6 · Recovery + lessons

    • Hardening recommendations
    • Detection improvements
    • Tabletop exercise replay (optional)
Closure + retest
Deliverables

What you get when the incident closes

  • Executive incident summary
  • Detailed forensic report (court-admissible)
  • CERT-In incident report (6-hour timeline)
  • Insurance documentation
  • Eradication + recovery plan
  • Tabletop exercise (post-incident)
Industries

Sectors we operate in

BFSIHealthcareManufacturing (post-ransomware)Government / PSUSaaS
What clients say · Trusted India + UAE

Empanelled by CERT-In. Accredited by EC-Council.

CERT-In Empanelled
Govt of India · MeitY
EC-Council ATC
Authorized Training
ISO 27001 Certified
Info Security Mgmt
CompTIA Authorized Partner
Training Delivery
We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.
LF
Information Security Manager
Listed Fintech · BKC, Mumbai
The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.
MP
Cyber Cell
Maharashtra Police · Mumbai
Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.
HS
DevSecOps Lead
Healthcare SaaS · Hyderabad
FAQ

When the call comes in.

Initial bridge call within 30 minutes for retainer clients, within 2 hours for new clients. Forensic team on-ground within 24 hours anywhere in India / UAE.
Yes — we draft the CERT-In report in the prescribed format and timeline (6 hours for major incidents).
Delivery footprint

Where Macksofy delivers DFIR.

On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.

References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • Thousands of professionals trained
  • India + UAE engagements