DFIR LABS AUSTRALIA
SERVICES

Fixed-scope engagements, built for how these matters actually arrive

Every engagement is scoped up front against a defined set of evidence sources and deliverables - no open-ended retainers.

Engagement Types

Three ways to engage

01

Incident Response

Investigation of a specific security incident - compromise, unauthorised access, or data exposure - from evidence collection through to reportable findings.

02

Workplace Investigation

Independent digital evidence review for contested employment matters, including cases where prior analysis is in dispute.

03

Expert Opinion

Independent expert report and, where required, testimony - prepared for legal counsel and built to withstand cross-examination.

How An Engagement Runs

From first contact to final report

Timelines vary by matter - this is the typical shape for an incident response engagement.

STEP 1 Scope Short briefing/call to understand the ivnestigation and discuss next steps.
STEP 2 Preserve Identify and preserve evidence sources (including devices, cloud, and logs) before anything is altered.
STEP 3 Initial Findings Preliminary examination and analysis to support reporting deadlines. If time-critical
STEP 4 Investigate Full analysis in-line with agreed scope.
STEP 5 Report Executive summary, technical analysis, and summary of findings.
Evidence We Work From

Built around what most organisations already have

Physical Device Forensics Workstation, server, and mobile device acquisition where required by the matter.
Cloud Azure, Microsoft 365, AWS Cloud-native assets including infrastructure, unified audit logs, mailbox audits, sign-in and access logs.
Network SIEM / Endpoint Where a SIEM or EDR platform exists, we can work from it directly.
Identity Entra ID Authentication, conditional access, and directory audit trails.

Need an independent finding on a live matter?

Tell us what you're dealing with. Most engagements start with a short scoping call before anything is committed.