Skip to content
IR 24/7 · Every minute counts

Incident Response & Digital Forensics

When a breach occurs, every minute counts. 24/7 SOC under NIST SP 800-61 and digital forensics with chain of custody for court — integrated on a single page.

Overview

Berghem's response program covers the entire incident cycle — from preparation with playbooks and tabletops, to containment in hours via 24/7 SOC, to forensic investigation that reconstructs the kill chain and produces a signed expert report for court. All under NIST SP 800-61 and ISO/IEC 27037.

Every action is logged, every decision is documented, and every artifact preserves chain of custody. We close with post-incident review, playbook updates, and indicators of compromise ready to feed your SIEM, EDR, and internal threat intel — closing the cycle in a way that reduces detection and containment time for the next event.

Everything included

24/7 SOC with rotating on-call
NIST SP 800-61 cycle (6 phases)
Containment within 4 hours
Forensic disk and memory acquisition
Malware reverse engineering
Chain of custody ISO/IEC 27037
Expert report signed by judicial expert
Module 01 · NIST SP 800-61

Incident Response

Six phases executed by a 24/7 SOC — from preparation to post-incident. Every minute is logged, every decision is documented, and every action preserves chain of custody.

Phase 01 · Playbook

Preparation

Response plan, team training, and tabletop exercises to ensure readiness before the incident — scenario-specific and business-area playbooks.

Phase 02 · SIEM · EDR

Detection & Analysis

Rapid identification and classification via SIEM, EDR, and threat intel — multi-source correlation to separate noise from real compromise and prioritize response.

Phase 03 · Isolation

Containment

Host isolation, credential revocation, and blast radius limitation — all while preserving evidence for subsequent forensics and audit.

Phase 04 · Cleanup

Eradication

Complete threat removal from the environment and closure of exploited attack vectors — focused hardening and integrity validation of compromised systems.

Phase 05 · Restoration

Recovery

Assisted restoration with enhanced monitoring to detect adversary return attempts — point-to-point validation before resuming normal operations.

Phase 06 · Post-mortem

Lessons Learned

Post-incident report, root cause analysis, and corrective actions — closing the cycle with playbook, control, and indicator updates that reduce the time of the next event.

Module 02 · ISO/IEC 27037

Digital Forensics

Investigation that withstands cross-examination: forensic acquisition, timeline reconstruction, and expert report signed by judicial expert. Six capabilities with auditable chain of custody.

Image · RAM · Artifacts

Disk & Memory

Write-blocked bit-by-bit images, volatile RAM capture, NTFS/EXT4 artifact analysis, and process dumps — the technical foundation of any serious forensic investigation.

PCAP · NetFlow · C2

Network Traffic

PCAP capture, NetFlow, session reconstruction, IOC extraction, and command-and-control server identification — recovering the complete history of adversarial communication.

Sandbox · MITRE ATT&CK

Malware & Reverse Engineering

Static and dynamic analysis in sandbox, unpacking, deobfuscation, and TTP mapping against MITRE ATT&CK — deep understanding of what the adversary actually did in the environment.

SIEM · EDR · IdP · Cloud

Logs & Timeline

Log correlation from SIEM, EDR, IdP, and cloud to reconstruct the kill chain minute by minute — from initial access to exfiltration, with court-admissible evidence.

ISO/IEC 27037 · SHA-256

Chain of Custody

ISO/IEC 27037 procedures with SHA-256 hashing, digital seals, and auditable trail of every piece of evidence — from collection to court presentation.

Report · Expertise · Court

Judicial Expert & Report

Signed expert report, technical court assistance, and specialized testimony — investigation that withstands cross-examination and supports legal accountability.

Active incident?

If you are facing a security incident right now, contact us immediately to activate 24/7 emergency response.

Contact emergency response