TechForensiq Forensics

Account and cloud forensics investigations

We investigate compromised cloud tenants and user accounts, reconstruct attacker sessions, and identify what was accessed or changed.

Encrypted channel ready

Signs you need this

When organisations call us

  • Sign-ins from unexpected locations or devices
  • New admin accounts, app registrations, or forwarding rules
  • Files downloaded in bulk from cloud storage
  • Unclear blast radius after a phishing incident

What you receive

Clear deliverables, no vague promises

  • Sign-in and audit log analysis
  • Session, token, and OAuth grant review
  • Persistence mechanism identification
  • Data access and download scoping
  • Containment and recovery checklist
  • Configuration hardening recommendations

How it works

A process built on evidence

  1. 01

    Preserve logs

    Cloud audit data is exported before retention windows close.

  2. 02

    Reconstruct

    We rebuild attacker sessions and every action performed.

  3. 03

    Contain

    Persistence is removed and credentials are rotated in a controlled order.

  4. 04

    Harden

    Identity and access configuration is tightened to prevent recurrence.

FAQ

Questions we are asked most

It depends on your licence tier and retention settings. We advise on this during intake.

Need clarity fast?

Whether you're a website owner, product team, or business leader, we'll expertly help you investigate, assess, and secure what matters most.

  • 24/7 secure intake
  • Confidential and discreet
  • Rapid expert response

We respect your privacy. No spam. Ever. Or email support@techforensiq.com