Fixed-scope engagement

Find out how much of an attack you could actually reconstruct.

The Forensic Horizon Assessment is a fixed-scope engagement that measures how far back your organization can investigate, validates that capability technically, and names the changes that extend it, measured against the attack scenarios that matter to your environment.

Delivered as

  • Defined scope agreed before start
  • Technical validation, not questionnaire only
  • Findings written in investigative terms
  • Baseline retained for later re-measurement
Request an Assessment

Who it is for

Organizations with established tooling and unproven investigative capability.

The assessment assumes a security stack already exists. It is designed for environments where SIEM, EDR, identity and network telemetry are in place, but where nobody has yet established what could actually be reconstructed after a serious incident.

Security leadership

Needs a defensible statement of investigative capability for the board, regulators or internal audit.

Incident response owners

Need to know which evidence will exist before an incident forces the question.

Architecture and engineering

Need a prioritized basis for retention, coverage and telemetry decisions.

Scope

What is assessed

Assessment areaTypical sources examined
IdentityActive Directory, Entra ID, PAM, MFA records
EndpointEDR / XDR detail, OS audit policy, process telemetry
NetworkFirewall, VPN, proxy, DNS, DHCP, NetFlow
CloudControl-plane audit, workload and storage access logs
EmailMessage trace, mailbox auditing, transport rules
Core infrastructureDirectory services, virtualization, backup platforms
Critical applicationsApplication and database audit records
OT / ICSWhere applicable to the environment

Assessment covers, per source

  • Coverage
  • Real retention
  • Accessibility
  • Evidence quality
  • Field fidelity
  • Detection usage
  • Ownership
  • Validation status

Configuration claims are recorded, then tested. A source is only reported as available for a period once that period has been examined.

Threat scenarios

Scenarios are selected before measurement begins.

Measurement is meaningless without a scenario. Scope discussion establishes which incidents the organization must be able to reconstruct, and the assessment measures against those.
ScenarioRepresentative investigative questions
RansomwareWhen did initial access occur? What executed? Which systems were reached laterally? Was data staged or exfiltrated before encryption?
Privileged Account CompromiseWhich identity was compromised? Was credential material extracted? Which privileged operations were performed?
Microsoft 365 Account CompromiseHow was the account accessed? Were mail rules or delegations created? What data was accessed or downloaded?
Data ExfiltrationWhich data was collected, from where, over which channel, and in what volume?
Persistent CompromiseHow long was the attacker present? Which persistence mechanisms were established? Which of them remain?

Method

Evidence analysis and technical validation

Two distinct phases. Analysis establishes what should be available; validation establishes what actually is.

Phase A: Evidence analysis

  • Asset and telemetry inventory reconciliation
  • Investigative question decomposition per scenario
  • Evidence dependency mapping, load-bearing vs corroborating
  • Retention, accessibility and ownership review

Phase B: Technical validation

  • Historical queries executed against each load-bearing source
  • Field-level inspection for attribution-critical detail
  • Coverage sampling across asset groups and segments
  • Assurance level assigned per source (E0-E4)

Outputs

What you receive

  • Threat scenario analysis
  • Evidence-source mapping
  • Forensic horizon measurement
  • Scenario reconstruction analysis
  • Technical evidence validation
  • Critical blind spot identification
  • Prioritized improvement roadmap
  • Management-ready reporting
  • Initial Forensic Horizon platform baseline

Typical engagement structure

  1. 01Scope discussionScenarios, environments and access agreed.
  2. 02DiscoveryInventory, telemetry and retention data collected.
  3. 03AnalysisEvidence dependencies mapped per investigative question.
  4. 04ValidationHistorical queries and coverage sampling performed.
  5. 05ReportingFindings, measured baseline and roadmap delivered.
  6. 06ReviewTechnical and management readouts.

Reporting

Two report layers are produced from one dataset: a technical report containing source-level records, executed validations and blind spot findings; and a management report stating measured investigative capability, the scenarios evaluated, and the prioritized changes with their projected effect.

Engagement

If the attacker arrived 90 days ago, how much could you still prove?

Scenarios, environments and validation depth are agreed before any measurement work starts.