When the Breach Happens, We Provide the Answers.
Memory, artefact and trace analysis to establish what happened, how far it went, and what to do next.
Last updated: July 2026
The Operational Reality
When an incident occurs, the pressure is immense. Whether you are dealing with a suspected internal breach, an automated ransomware attack, or a request from a law firm to preserve digital evidence, you need a forensic approach that is technically precise and legally sound. Clean, well-preserved evidence also supports any cyber insurance claim that follows.
Using our internal GCFA-certified expertise, we make sure that forensic artefacts such as memory dumps, system logs, and file system metadata are analysed to the highest industry standards, combining automated tooling with rigorous manual investigation.
The Forensic Trace
Every action an attacker takes leaves a mark. We follow the breadcrumbs, linking each system event to the forensic artefacts left behind, to reconstruct exactly what happened. There is nowhere to hide.
Account Logon
An attacker uses compromised or brute-forced credentials to authenticate to a workstation or server.
Authentication leaves a durable record across the OS and directory services.
Program Execution
A malicious binary or living-off-the-land tool is run to establish a foothold on the host.
Windows records what ran, when, and from where, even after deletion.
File Modification
Sensitive documents are created, altered, staged for theft, or encrypted by ransomware.
The file system and journals preserve a precise timeline of every change.
Network Connection
The host beacons to a command-and-control server or exfiltrates data to an external endpoint.
Connection state and DNS resolution are captured in memory and on disk.
Persistence
The attacker plants a mechanism to survive reboots and maintain long-term access.
Auto-start locations and scheduled tasks expose how the foothold is held.
Anti-Forensics
Logs are cleared and timestamps tampered with in an attempt to cover the attacker's tracks.
Even the act of hiding leaves its own tell-tale signature behind.
The matters we take
Most of our work is smaller than the engagements large forensic firms are built around, and that is deliberate. A single laptop, a departed employee's mailbox, a disputed set of files, or one server that behaved strangely on a particular Tuesday. Those matters are too small for a firm with an enterprise minimum, and they are exactly where a business needs an answer it can rely on.
Two situations account for most of what we see: someone inside the business took something, or someone outside got in. Both come down to the same question, which is what the records actually show.
Insider threat and employee departures
The most common matter we see. A staff member leaves and a client list, a design file or a pricing sheet appears to have gone with them. We examine the devices and accounts you control to establish what was accessed, what was copied, where it went and when, and document it so the findings hold up if the matter goes further.
Employment and workplace disputes
Where an allegation turns on what someone did on a company system, the record usually exists. We reconstruct the activity from the artefacts rather than from assumptions, which protects the employee as often as it protects the employer, and give you findings a lawyer can work with.
Business disputes and contractual matters
Questions about who had access to what, whether documents were altered, or what a system's records show at a given date. We establish the sequence of events and set out how we reached it.
Post-incident forensic post-mortem
After an intrusion or a ransomware event, the urgent work is getting running again, and the question that matters afterwards is what happened and whether it is over. We establish the entry point, how long the intruder was present, what they reached, whether data left the business, and whether any access remains. Those four answers decide what you tell customers, what you tell your insurer, and whether you are about to be hit a second time through the same door.
The post-mortem is also where an incident stops being a loss and becomes something useful. Findings feed straight into what to fix first, and clean, well-preserved evidence supports any cyber insurance claim that follows, which our cyber insurance requirements page covers in more detail. Where a response is still running, our incident response training page covers rehearsing the next one.
What we do not take
We work commercial matters only. We do not act in criminal proceedings, for the prosecution or the defence, and we do not take instructions from law enforcement. Where a matter is criminal in nature, the right path is a firm that specialises in it, and we will say so early rather than partway through.
Investigations often reach beyond company systems, because work moves onto personal phones and personal mail accounts. What is available to examine in those situations is specific to the matter and to the law that applies to it, and it is your solicitor who determines that rather than us. We work within what your solicitor confirms is available, and we will raise the question early rather than partway through, because scope decided properly at the start is what keeps the findings usable later.
Our Architectural Approach
We provide forensic clarity so you can make informed decisions, turning a moment of chaos into a structured, defensible account of what occurred.
Forensic insights serve the incident at hand and everything after it. Every finding strengthens your long-term posture against the specific tactics discovered during our analysis.
Rapid Investigation
We scope the incident fast, confirming whether data was exfiltrated, identifying the initial attack vector, and verifying if the threat actor still has persistent access.
Forensic Preservation
We establish the procedures to capture and preserve evidence securely, keeping the chain of custody intact should the matter escalate to legal or insurance proceedings.
Operational Integration
Lessons from each investigation feed directly into your Quarterly Strategic Reviews, hardening your architecture against the exact tactics we uncovered.
Our Strategic Advisory Model
Vintaris is an architectural and advisory firm. While we provide expert forensic analysis and investigative support, we are not an automated, 24/7 incident-response "firefighting" team. If you are in an active crisis, we help you use the right response channels, providing the technical rigour to manage the fallout without massive enterprise retainers.
GCFA-Certified Analysis
GCFA-certified examination of memory dumps, system logs and file-system metadata, carried out in house by the analyst who scoped the matter.
Tailored for SMBs
A high-performance forensic service structured for your scale and budget, without prohibitive retainers or hourly rates.
Law Firm Support
Specialised support for legal practices, investigating and preserving evidence for disputes, employment matters, and contractual inquiries.
Sound Chain of Custody
Evidence is captured and documented so your findings remain robust through legal or insurance-driven investigations.
Manual + Automated
We pair advanced automated tooling with disciplined manual investigation to follow every breadcrumb to its source.
Architectural Feedback Loop
Findings feed directly into your Quarterly Strategic Reviews, hardening your defences against the tactics we uncover.
Before you call anyone, stop touching it
The most common reason a forensic question cannot be answered is that the evidence was destroyed by well-meaning people in the first hour. Rebuilding the machine, running a clean-up tool, logging in to have a look, or handing the laptop back to the employee all overwrite the record of what happened.
Isolate the device and leave it alone
If you think you may need forensic evidence, take the device out of use and stop anyone working on it. Every login and clean-up overwrites part of the record.
Ask before shutting anything down
Power state matters. Memory contents are lost on power-off and are sometimes the only place the answer lives, so check before powering anything down.
Preserve the accounts too
Mailbox and cloud logs often expire on a retention clock that is shorter than the time it takes to decide you need them. Preserve them alongside the device.
Our incident response plan template sets out these steps in a form you can hand to whoever picks up the phone first.
Why Vintaris for Forensics?
Every investigation is carried out in house by a GCFA-certified analyst, so the person examining your evidence is the person who explains it to you. That is what turns a confusing situation into a clear account you can act on and rely on later.
Your examiner: Alexandra Gada, GCFA
GIAC Certified Forensic Analyst (GCFA)Investigations are led by Alexandra Gada, a GIAC Certified Forensic Analyst. The GCFA is an advanced practitioner certification covering incident forensics, intrusion analysis and evidence handling, and it is held personally rather than by the firm. In practice that means the analyst who examines your evidence is the one who scoped the matter, reached the findings, and will explain them to your lawyer or your insurer if asked.
Before founding Vintaris, Alexandra Gada worked as an analyst in CrowdStrike's Falcon Complete managed detection and response team, investigating live intrusions across customer environments rather than studying them afterwards. That background is the reason the post-incident work on this page is framed the way it is.
Matters are examined in house by default. Where a case is larger than one examiner can carry, or calls for a discipline outside our own, we bring in specialist forensic professionals based in Australia. We engage them ourselves, we tell you when we are doing it, and the chain of custody and the accountability for the findings stay with us. Your material stays onshore in every case.

Frequently asked questions
What does a digital forensics investigation cost?
It depends on the number of devices and accounts, how much data each holds, and how far the questions go. A single-device examination with a focused question is a small engagement; a matter spanning several custodians, cloud accounts and a long time period is a larger one. We scope in writing before starting, so you are not exposed to an open-ended hourly meter.
What is chain of custody, and why does it matter?
It is the documented record of who handled the evidence, when, and what was done to it, from collection through to analysis. Without it, the other side can argue the evidence was altered, and a finding that cannot survive that challenge has little value. We maintain it on every matter, including ones that never reach a lawyer, because you rarely know at the start which ones will.
An employee used their own phone for work. Can you examine it?
That depends on the matter rather than on the technology, and it is a question for your solicitor before it is a question for us. The law in this area is tight and the answer turns on the specifics, so we work within what your solicitor confirms is available to examine. Raise it with them early, because scope settled at the start is what keeps findings usable later.
Do you take criminal matters?
No. We work commercial matters only, and we do not act for the prosecution, the defence, or law enforcement. If a matter is criminal in nature we will tell you early and point you towards firms that specialise in it.
Who actually carries out the investigation?
A GCFA-certified analyst inside Vintaris, named on this page, and by default the same person scopes the matter, does the analysis and writes the report. Larger matters, or ones needing a discipline outside our own, may involve specialist forensic professionals we engage directly, all based in Australia. We tell you when that happens, we stay accountable for the findings, and your material does not leave the country.
Do you work with law firms?
Yes, and a good share of our work arrives that way. We take instructions from solicitors in employment and commercial matters, produce findings in a form that can be worked with, and are used to explaining technical detail to people who need to rely on it rather than reproduce it.
Are you available outside Brisbane?
Yes. Some collections need physical access to a device and we arrange that as the matter requires, while a good deal of examination work can be done from properly collected images and cloud data without anyone travelling. We will tell you at scoping which parts of your matter need hands on the device.
How quickly can you start?
Faster than most, because the work starts in house rather than joining a queue somewhere else. If you have a live situation, the most useful thing you can do before we speak is stop using the device and leave it powered as it is.
What is digital forensics?
It is the examination of digital devices and accounts to establish what happened, using the traces that systems record automatically. Those records are far more detailed than most people expect, and they are also easy to destroy accidentally, which is why the first hour matters.
Ready to gain the forensic clarity you need?
Talk to us about your matter. We will tell you early whether it is one we can help with, and what preserving the evidence looks like from here.
Let's Talk SecurityNot sure where your gaps are yet? Start with a cyber security assessment.
Worried, but no live matter yet?
Worried something may already be wrong in your systems? A quick check is a sensible first step, and it points you to where to look before anything becomes an investigation.
Start the free 2-minute checkWhere are your passwords kept?
Pick the closest to reality, not the ideal.
Prepared and reviewed by the Vintaris security team.
Vintaris provides digital forensic examination and advisory services for commercial matters. Vintaris does not act in criminal proceedings or for law enforcement. Nothing on this page is legal advice, and whether particular material may lawfully be examined is a question for your legal adviser.