When the worst happens, every minute matters.
Macksofy's DFIR team responds to ransomware, business email compromise, insider threats and APT intrusions across India and the GCC. Court-admissible chain of custody, structured Velociraptor + KAPE collection, expert reporting for regulators, insurers and law enforcement.
What is DFIR?
DFIR (Digital Forensics and Incident Response) is the discipline of containing a live cyberattack, investigating how it happened, and recovering safely — covering ransomware, business email compromise, and Active Directory compromise. Macksofy's GCFA/GREM/CHFI-certified team responds across India, preserves evidence, and files CERT-In incident reports.
T+0 → T+7d. Every minute documented.
Anonymised composite from the typical Macksofy ransomware engagement — what happens at each clock-tick from the moment your CISO hits the hotline.
- Contain incidents in hours, not weeks
- Preserve evidence for legal / regulatory action
- Satisfy CERT-In incident reporting requirements (6-hour rule)
- Reduce insurance claim disputes via proper documentation
Triage call
T+030-min bridge · scope · isolate · engagement letter
Evidence collection
T+2hVelociraptor agents · KAPE offline · cloud log preservation
Live analysis
T+8hVolatility 3 memory · Plaso timeline · IOC extraction
Containment
T+24hAttacker eviction · persistence removal · cred reset
CERT-In report
T+72h6-hour-rule compliant · insurance · legal-ready
Recovery + lessons
T+7dHardening plan · detection upgrades · tabletop replay
Evidence that survives court.
Every forensic artifact gets a SHA-256, a custodian signature and an encrypted storage chain — accepted by Indian courts, RBI investigations, CERT-In and cyber-insurance arbitrators.
FTK Imager · write-blocker · SHA-256 captured
Volatility 3 memory · network state · open handles
Encrypted storage · access log · custodian signed
Air-gapped lab · Autopsy · Plaso timeline
Chain log · expert testimony · CERT-In format
Ransomware · BEC · insider threat.
Ransomware (LockBit variant)
Root cause · Initial access via exposed RDP + leaked creds; lateral movement via PsExec
Containment in 11h; 80% of systems restored from backups within 72h
Volatility · Plaso. Real DFIR tools.
Rated 4.9 ★ from 612 client reviews.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
When the call comes in.
Where Macksofy delivers DFIR.
On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.
Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- 20,000+ professionals trained
- India + UAE engagements
