TechForensiq Forensics
Account and cloud forensics investigations
We investigate compromised cloud tenants and user accounts, reconstruct attacker sessions, and identify what was accessed or changed.
Signs you need this
When organisations call us
- Sign-ins from unexpected locations or devices
- New admin accounts, app registrations, or forwarding rules
- Files downloaded in bulk from cloud storage
- Unclear blast radius after a phishing incident
What you receive
Clear deliverables, no vague promises
- Sign-in and audit log analysis
- Session, token, and OAuth grant review
- Persistence mechanism identification
- Data access and download scoping
- Containment and recovery checklist
- Configuration hardening recommendations
How it works
A process built on evidence
- 01
Preserve logs
Cloud audit data is exported before retention windows close.
- 02
Reconstruct
We rebuild attacker sessions and every action performed.
- 03
Contain
Persistence is removed and credentials are rotated in a controlled order.
- 04
Harden
Identity and access configuration is tightened to prevent recurrence.
FAQ
Questions we are asked most
It depends on your licence tier and retention settings. We advise on this during intake.
Related
Continue exploring
Need clarity fast?
Whether you're a website owner, product team, or business leader, we'll expertly help you investigate, assess, and secure what matters most.
- 24/7 secure intake
- Confidential and discreet
- Rapid expert response
We respect your privacy. No spam. Ever. Or email support@techforensiq.com