What we did
Reconstructed an live exfiltration by following data across a packet capture, extracting transferred files from the protocol stream, and unwinding nested/encrypted archive layers to recover the payload. The work is methodical: identify the protocol, follow the stream, carve the artifact, repeat through each layer.
- Reading and filtering packet captures to isolate the relevant conversation
- Extracting and carving transferred files from network and disk artifacts
- Unwinding layered / password-protected archives to reach the payload
Why it matters to a client
When something goes wrong, forensics answers "what did they take and how." The same skills support incident triage, verifying whether an exposure led to data movement, and understanding attacker activity in your logs and captures.
← Back to case studies