When a company enters the Corporate Insolvency Resolution Process (CIRP),…
Read MoreA cyber-attack does not end when the attacker leaves. In many ways, that is when the real work begins. Whether your organisation has suffered a ransomware infection, a data breach, unauthorised access, or an insider threat incident, the actions taken in the hours and days that follow will determine whether you recover quickly — and whether justice can be served.
At Stellar Forensic, we conduct end-to-end digital forensic investigations for corporates, legal teams, and law enforcement agencies across India. This guide walks you through exactly what a professional cyber-forensic investigation looks like — from the moment an incident is reported to the delivery of court-ready evidence.
Step 1: Incident Identification & Triage
The forensic process begins with confirming that an incident has actually occurred and understanding its scope. Not every alert is an attack, and not every breach is immediately visible. During triage, our team focuses on:
- Reviewing initial indicators of compromise (IoCs) — unusual login times, unexpected outbound traffic, disabled security tools
- Classifying the incident type (ransomware, data exfiltration, insider threat, phishing, etc.)
- Assessing the systems, networks, and data likely impacted
- Engaging stakeholders — legal counsel, IT security, HR, and senior management as needed
Pro tip: Do NOT restart affected systems or run antivirus scans before a forensic team arrives. These actions can overwrite volatile evidence that exists only in RAM.
Step 2: Legal Hold & Evidence Preservation
Before any data is collected, a Legal Hold must be established. This ensures all relevant electronic data is preserved and cannot be altered, deleted, or overwritten — intentionally or accidentally.
What we preserve:
- Live system memory (RAM) — contains active processes, encryption keys, and network connections
- Disk images — forensic bit-for-bit copies using tools like FTK Imager or EnCase
- Network logs, firewall logs, and SIEM data
- Email servers, cloud storage, and collaboration platforms
- Mobile devices and endpoint data where relevant
Every acquisition is hash-verified (MD5 + SHA-256) and documented to establish an unbroken chain of custody — a requirement for evidence to be admissible under Indian courts and the IT Act, 2000.
Step 3: Forensic Acquisition
Forensic acquisition is the controlled, documented collection of digital evidence. Unlike a simple file copy, forensic acquisition captures every bit of data — including deleted files, unallocated disk space, and file system metadata.
Stellar Forensic uses industry-standard tools including EnCase, FTK, X-Ways Forensics, and Magnet AXIOM for acquisition across Windows, Linux, macOS, iOS, and Android platforms. All acquisitions are performed using write-blockers to ensure the original evidence is never modified.
Step 4: Analysis & Examination
This is the most intensive phase. Our forensic analysts work on verified copies of the evidence (never the originals) to reconstruct what happened, when it happened, and who was responsible.
Key analysis activities:
- Timeline analysis — reconstructing the attack sequence using file metadata, event logs, and registry artefacts
- Malware analysis — identifying malicious files, scripts, or executables deployed by the attacker
- Network forensics — examining packet captures and flow data for data exfiltration or command-and-control activity
- User activity analysis — determining which accounts accessed what, and when
- Data recovery — recovering deleted, encrypted, or overwritten files relevant to the investigation
- Email & communication forensics — tracing phishing origins, internal data leakage, or fraud
Step 5: Chain of Custody Documentation
Every piece of evidence handled during an investigation must have a documented chain of custody. This record tracks who collected the evidence, when it was collected, how it was stored, and everyone who accessed it thereafter.
A break in the chain of custody can render evidence inadmissible in court — regardless of how compelling it may be. As an ISO 9001:2015 and ISO 27001:2022 certified firm, Stellar Forensic follows rigorous documentation procedures that satisfy both corporate compliance requirements and judicial standards.
Step 6: Reporting
Once analysis is complete, findings are compiled into a structured Forensic Investigation Report. This document is written to serve multiple audiences — legal counsel, the judiciary, corporate management, and regulators — while remaining technically precise.
A professional forensic report includes:
- Executive summary for non-technical stakeholders
- Detailed methodology and tools used
- Timeline of events with forensic evidence supporting each finding
- Identified indicators of compromise (IoCs)
- Attribution findings where possible
- Impact assessment — data affected, systems compromised, duration of breach
- Recommendations for remediation and future prevention
Step 7: Expert Testimony & Legal Support
In matters that proceed to litigation, arbitration, or regulatory proceedings, Stellar Forensic’s investigators are available to provide expert testimony — explaining technical findings in clear, accessible language for judges, arbitrators, and legal panels.
Our reports are prepared in accordance with the Indian Evidence Act, the IT Act, 2000, and the DPDPA 2023 framework, ensuring they meet the standards required for admissibility as electronic evidence.
How Long Does a Forensic Investigation Take?
Timeline varies significantly based on the scale of the incident. A targeted investigation involving a single compromised endpoint can be concluded in 3–5 business days. Enterprise-scale breaches involving multiple systems, large datasets, or cross-border elements may take several weeks.
Stellar Forensic offers rapid deployment for urgent matters. Early engagement is always better — the longer the wait, the greater the risk that volatile evidence is lost.
Frequently Asked Questions
Can deleted files be recovered after a cyber attack?
In many cases, yes. Deleted files often remain recoverable from unallocated disk space until the space is overwritten. Forensic tools can recover substantial data even from formatted drives, provided the device is preserved promptly.
Will a forensic investigation disrupt our operations?
We design our acquisition process to minimise operational disruption. In most cases, forensic copies can be taken with minimal downtime. Our team works around your business requirements wherever possible.
Is digital evidence legally admissible in Indian courts?
Yes, provided it is collected and handled in accordance with the Indian Evidence Act (Section 65B) and the IT Act. This is precisely why professional, certified forensic investigation matters — improperly handled evidence is frequently challenged and excluded.
We suspect an insider. Can you investigate without alerting them? Yes. Insider threat investigations are conducted discreetly. We work closely with HR and legal counsel to ensure the investigation is both effective and legally defensible.
Has your organisation experienced a cyber incident?
Stellar Forensic provides rapid, ISO-certified digital forensic investigations across India. The sooner you engage a professional forensic team, the better the outcome.
Contact us: info@stellarforensic.com | www.stellarforensic.com