When the worst happens, every minute matters.
Macksofy's DFIR team responds to ransomware, business email compromise, insider threats and APT intrusions across India and the GCC. Court-admissible chain of custody, structured Velociraptor + KAPE collection, expert reporting for regulators, insurers and law enforcement.
What is DFIR?
DFIR (Digital Forensics and Incident Response) is the discipline of containing a live cyberattack, investigating how it happened, and recovering safely — covering ransomware, business email compromise, and Active Directory compromise. Macksofy's GCFA/GREM/CHFI-certified team responds across India, preserves evidence, and files CERT-In incident reports.
T+0 → T+7d. Every minute documented.
Anonymised composite from the typical Macksofy ransomware engagement — what happens at each clock-tick from the moment your CISO hits the hotline.
- Contain incidents in hours, not weeks
- Preserve evidence for legal / regulatory action
- Satisfy CERT-In incident reporting requirements (6-hour rule)
- Reduce insurance claim disputes via proper documentation
Triage call
T+030-min bridge · scope · isolate · engagement letter
Evidence collection
T+2hVelociraptor agents · KAPE offline · cloud log preservation
Live analysis
T+8hVolatility 3 memory · Plaso timeline · IOC extraction
Containment
T+24hAttacker eviction · persistence removal · cred reset
CERT-In report
T+72h6-hour-rule compliant · insurance · legal-ready
Recovery + lessons
T+7dHardening plan · detection upgrades · tabletop replay
Evidence that survives court.
Every forensic artifact gets a SHA-256, a custodian signature and an encrypted storage chain — accepted by Indian courts, RBI investigations, CERT-In and cyber-insurance arbitrators.
FTK Imager · write-blocker · SHA-256 captured
Volatility 3 memory · network state · open handles
Encrypted storage · access log · custodian signed
Air-gapped lab · Autopsy · Plaso timeline
Chain log · expert testimony · CERT-In format
Ransomware · BEC · insider threat.
Ransomware (LockBit variant)
Root cause · Initial access via exposed RDP + leaked creds; lateral movement via PsExec
Containment in 11h; 80% of systems restored from backups within 72h
Volatility · Plaso. Real DFIR tools.
Every hour accounted for.
- Phase 01
1 · Triage call
- 30-minute bridge call to scope the incident
- Initial containment guidance (network isolation, etc.)
- Engagement letter + RoE for forensic work
01Station 0101Phase 011 · Triage call
- 30-minute bridge call to scope the incident
- Initial containment guidance (network isolation, etc.)
- Engagement letter + RoE for forensic work
- Phase 02
2 · Evidence collection
- Velociraptor agents deployed (or KAPE for offline)
- Memory + disk imaging where required
- Cloud log preservation (CloudTrail, Activity Log, Audit Log)
02Station 0202Phase 022 · Evidence collection
- Velociraptor agents deployed (or KAPE for offline)
- Memory + disk imaging where required
- Cloud log preservation (CloudTrail, Activity Log, Audit Log)
- Phase 03
3 · Analysis
- Timeline construction (Plaso / log2timeline)
- Memory analysis (Volatility 3)
- Malware triage + IOC extraction
- Lateral movement reconstruction
03Station 0303Phase 033 · Analysis
- Timeline construction (Plaso / log2timeline)
- Memory analysis (Volatility 3)
- Malware triage + IOC extraction
- Lateral movement reconstruction
- Phase 04
4 · Containment + eradication
- Attacker eviction plan
- Persistence mechanism removal
- Credential reset orchestration
04Station 0404Phase 044 · Containment + eradication
- Attacker eviction plan
- Persistence mechanism removal
- Credential reset orchestration
- Phase 05
5 · Reporting
- Executive incident summary
- Technical forensic report
- CERT-In incident report (6-hour rule compliance)
- Insurance + legal-ready documentation
05Station 0505Phase 055 · Reporting
- Executive incident summary
- Technical forensic report
- CERT-In incident report (6-hour rule compliance)
- Insurance + legal-ready documentation
- Phase 06
6 · Recovery + lessons
- Hardening recommendations
- Detection improvements
- Tabletop exercise replay (optional)
06Station 0606Phase 066 · Recovery + lessons
- Hardening recommendations
- Detection improvements
- Tabletop exercise replay (optional)
What you get when the incident closes
- Executive incident summary
- Detailed forensic report (court-admissible)
- CERT-In incident report (6-hour timeline)
- Insurance documentation
- Eradication + recovery plan
- Tabletop exercise (post-incident)
Sectors we operate in
Empanelled by CERT-In. Accredited by EC-Council.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
When the call comes in.
Where Macksofy delivers DFIR.
On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.
Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- Thousands of professionals trained
- India + UAE engagements
