- Capability
- Incident Response & DFIR
- Lead
- Joey Victorino — personally led
- Basis
- Engaged during or after an incident · evidence preserved first
- Contact
- joey@victori.no
When the evidence must explain what happened.
An intrusion is active, or it has been declared contained and the evidence still does not explain what happened. Work can begin during the incident or after another team has closed it.
What I do
Incident response & forensics
Forensic acquisition, timeline reconstruction, endpoint and identity analysis, breach scoping, malware triage, persistence analysis, containment, and recovery.
Threat hunting
Hypothesis-driven hunting across authentication, control planes, workloads, and telemetry when alerts are insufficient or the scope is uncertain.
Post-incident evidence review
What the investigation record supports, what it does not, and what was never examined.
For the board-level closure question, see the Incident Closure Review.
What you get
A stabilized incident, evidence preserved before it decays, and a written account that separates what is known from what is inferred. The questions still open are named, not smoothed over.
It arrives as a written conclusion in the format of the sample memorandum: the question, the evidence reviewed, the assumptions it rests on, the findings, the unknowns, and what to do next. You can read that format before you call.