Forensics tells you what happened. An investigation tells you who.
When the incident has a human author.
Lawful OSINT attribution, endpoint forensics, and structured interviews — combined into one engagement, with every finding sourced, confidence-rated, and preserved so your counsel can actually use it.
3
OSINT · forensics · interview
10 days
Typical attribution engagement
Sourced
Every finding, confidence-rated
Attribution assessment
Matter · unauthorized disclosure
Corroborating findings
Evidence timeline
Assessment
Evidence supports attribution to with high confidence. Five independent sources corroborate; no single finding relied upon.
Sources logged · ISO/IEC 17025
Conducted to
Which one do you need
Two different questions. Two different teams.
Incident response reconstructs what happened to your systems. An investigation attributes an act to a person, to a standard that survives an HR process or a courtroom. Most serious insider matters need both — and they run best in that order.
Forensics establishes that 4.2 GB left via a USB device at 19:42. The investigation establishes whose hand was on it, and whether they can be shown to have intended it.
If it's happening right now
A live intrusion is an incident, not an investigation. Start with Incident Response & Digital Forensics — we can open an investigation alongside it once the bleeding stops.
IR & Digital Forensics
Question
What happened?
Subject
Systems & data
Trigger
A security incident
Buyer
CISO / SOC
Output
Timeline, root cause, recovery
Corporate Investigations
Question
Who did it — and why?
Subject
People & conduct
Trigger
A suspicion or allegation
Buyer
Legal / HR / board
Output
Attribution, evidence pack
When you need one
The matters that land on this desk.
Different facts, same underlying problem: something happened, a person is behind it, and the organization needs to know who before it can act.
Data leak with an insider suspicion
Confidential material is circulating and the access pattern points inward. Systems logs narrow it; they rarely name a person on their own.
Departing employee took the IP
Source code, client lists, or designs left with someone who resigned. The laptop is back, the password isn't, and HR needs something defensible.
Anonymous publication or leak site
Someone published about your company, your deal, or your people from behind a pseudonym — and you need to know who, and why.
Fraud, kickbacks & procurement abuse
Financial irregularity where the paper trail and the relationship map matter more than any single system.
Pre-deal & counterparty diligence
Establishing who you are actually contracting with, and what their public record says, before signing.
Grievance & misconduct escalation
An allegation that HR cannot resolve internally and that carries real legal exposure either way.
Three disciplines
The trail, the device, and the account.
Attribution rarely comes from one source. We run three lines of enquiry and reconcile them against each other — which is also what makes a finding defensible.
OSINT attribution
The public trail
Reconstruct the author's or subject's digital trail from lawfully accessible public sources — infrastructure and registration metadata, exposed identifiers, and cross-platform correlation — to converge on candidate identities.
- Publication & infrastructure analysis
- Identifier recovery (accounts, emails, metadata)
- Cross-platform correlation
- Footprint mapping & motive assessment
Endpoint forensics
The device record
Bit-for-bit forensic imaging of in-scope devices with chain of custody maintained from seizure, then reconstruction of what the user actually did — including what they tried to erase.
- Forensic imaging & controlled unlocking
- File copying, email forwarding, cloud uploads
- USB and external-device activity
- Deleted-file recovery & destruction indicators
Structured interview
The human account
Interviews with the personnel involved, conducted to a consistent methodology — and, where lawful and consented, polygraph examination as one supporting input among several.
- Structured, methodologically consistent interviews
- Consent-based examination where lawful
- Account reconciled against artifact evidence
- Findings reported without overstatement
On polygraph — stated plainly
We offer certified polygraph examination, and we describe it accurately. It measures physiological response during structured questioning — it does not detect lies directly, its accuracy is scientifically contested, and it is inadmissible as evidence in most courts, including Indonesian proceedings. Its value is investigative: it structures a difficult conversation and surfaces areas that warrant further examination.
How we use it
- One supporting input among several
- Never the sole basis for an adverse finding
- Informed written consent, always
- Only where lawful in the jurisdiction
- We advise against it where unwarranted
Method
Preserve first. Conclude last.
Evidence is captured and timestamped before any analysis begins, because an investigation that contaminates its own evidence is worse than none at all.
Scope & preserve
Confirm the subject, objective, and lawful boundaries with your authorized point of contact — then capture and timestamp evidence before any analysis begins.
Collect
Lawful OSINT across public sources and forensic acquisition of in-scope devices, with chain of custody documented throughout.
Correlate
Cross-reference identifiers, account activity, file movement, and device artifacts to converge on one or more candidate attributions.
Interview
Structured interviews with relevant personnel, reconciled against the artifact record rather than taken at face value.
Assess
Weigh the evidence and assign a confidence level to every finding — stating plainly what the evidence supports and what it does not.
Report & support
Deliver the attribution assessment and evidence pack, then support your counsel or HR process through to resolution.
The confidence model
Every finding is rated. No conclusion rests on a single unverified source.
Investigations go wrong when a plausible lead is presented as a fact. Each finding in our reports carries an explicit confidence level and the evidence behind it, so you and your counsel can weigh it properly.
High
Multiple independent sources corroborate the finding, with preserved evidence for each.
Moderate
Supported by credible evidence, with a plausible alternative explanation not fully excluded.
Low
Indicative only. Reported as a lead for further work, never as a conclusion.
Lawful by design
An investigation that breaks the law is worthless to you.
Evidence gathered unlawfully doesn't just fail in a tribunal — it exposes the organization that commissioned it. We work from public sources and from systems and devices you own and have authorized us to examine. Nothing else.
Collection is limited to what the lawful purpose requires, in line with UU PDP and, where Singapore is in scope, the PDPA. Investigations routinely touch employees who turn out to be uninvolved — protecting those people is part of doing this properly.
On admissibility
We preserve under ISO/IEC 17025 laboratory discipline so the evidence is as strong as it can be. We do not promise admissibility in any given jurisdiction — that is your counsel's determination, and anyone who tells you otherwise is overselling.
Explicitly out of scope
What we will not do.
- Unauthorized access to any system or account
- Interception of communications
- Social engineering of the subjects under investigation
- Surveillance or collection unlawful in the applicable jurisdiction
- Any use for harassment, intimidation, or coercion
We also require written warranty that findings will be used for lawful purposes — legal advice, disciplinary process, regulatory action — and not against any individual.
Preservation shouldn't wait
If a device is sitting in a drawer, the clock is already running.
Evidence degrades, gets overwritten, and gets challenged. A short confidential call establishes whether you have a matter worth investigating and what to preserve right now — before anything is decided.
Deliverables
Written to be used, not filed.
Five coordinated work products — for the executive who must decide, and the lawyer who must act.
Attribution assessment
Methodology, recovered identifiers, correlation, and the attribution itself — each finding stated with its confidence level and supporting evidence.
Subject profile & motive brief
The subject's public footprint, possible affiliations to the parties involved, and a reasoned assessment of intent based on content and timing.
Interview & examination findings
What was said, how it reconciles with the artifact record, and where accounts diverge from the evidence.
Evidence pack
Preserved copies, timestamps, and a complete source log supporting each finding — retained for your records and any subsequent legal use.
Executive summary & next steps
A non-technical briefing and a recommended course of action — legal escalation, platform takedown, disciplinary process, or further investigation.
Discretion
Findings go to your named point of contact only — not to the wider organization, and never to a third party.
Casework — anonymized
Unauthorized disclosure
Multi-subject examination programme run alongside artifact analysis in a live data-leak matter, with signed findings delivered to the client's leadership.
Anonymous publication
OSINT attribution of an anonymous publication naming a listed company and a signed commercial agreement — infrastructure, identifiers, and motive assessed.
Departing-employee IP theft
Forensic acquisition of returned devices, reconstruction of file movement and USB activity, and an evidence pack prepared for HR and legal action.
Clients, subjects, and identifying details withheld. Investigations are confidential by default.
Pairs with
Before, during, and after the matter.
Build the program
Pairs well with
Incident Response & Digital Forensics
The technical half. Forensics establishes what moved; the investigation establishes who moved it.
TSCM — Technical Surveillance Countermeasures
A sweep finds the device. An investigation finds the person who placed it.
Data Governance Implementation
Most insider incidents trace back to data nobody classified or access nobody reviewed.
Security Awareness & Phishing Simulation
After the matter closes — the control that reduces the next one.
FAQ
Straight answers on investigations
What legal, HR, and executive teams ask before opening a matter — including the questions we'd rather answer honestly than sell past.
They answer different questions. IR & Digital Forensics answers what happened to your systems — the intrusion timeline, root cause, containment, and recovery — and its client is usually the CISO. Corporate Investigations answers who did it and why, to a standard your HR process or your counsel can act on, and its client is usually Legal, HR, or the board. They often run together: forensics establishes that 4GB left via a USB device at 19:42, and the investigation establishes whose hand was on it. If you have a live intrusion right now, start with incident response; if you have a person to identify, start here.
Somebody did it. Let's establish who — properly.
A confidential conversation with the team that runs these matters. We'll tell you what's worth investigating, what to preserve today, and what the evidence is realistically likely to support.