Overview
Berghem's response program covers the entire incident cycle — from preparation with playbooks and tabletops, to containment in hours via 24/7 SOC, to forensic investigation that reconstructs the kill chain and produces a signed expert report for court. All under NIST SP 800-61 and ISO/IEC 27037.
Every action is logged, every decision is documented, and every artifact preserves chain of custody. We close with post-incident review, playbook updates, and indicators of compromise ready to feed your SIEM, EDR, and internal threat intel — closing the cycle in a way that reduces detection and containment time for the next event.
Everything included
Incident Response
Six phases executed by a 24/7 SOC — from preparation to post-incident. Every minute is logged, every decision is documented, and every action preserves chain of custody.
Preparation
Response plan, team training, and tabletop exercises to ensure readiness before the incident — scenario-specific and business-area playbooks.
Detection & Analysis
Rapid identification and classification via SIEM, EDR, and threat intel — multi-source correlation to separate noise from real compromise and prioritize response.
Containment
Host isolation, credential revocation, and blast radius limitation — all while preserving evidence for subsequent forensics and audit.
Eradication
Complete threat removal from the environment and closure of exploited attack vectors — focused hardening and integrity validation of compromised systems.
Recovery
Assisted restoration with enhanced monitoring to detect adversary return attempts — point-to-point validation before resuming normal operations.
Lessons Learned
Post-incident report, root cause analysis, and corrective actions — closing the cycle with playbook, control, and indicator updates that reduce the time of the next event.
Digital Forensics
Investigation that withstands cross-examination: forensic acquisition, timeline reconstruction, and expert report signed by judicial expert. Six capabilities with auditable chain of custody.
Disk & Memory
Write-blocked bit-by-bit images, volatile RAM capture, NTFS/EXT4 artifact analysis, and process dumps — the technical foundation of any serious forensic investigation.
Network Traffic
PCAP capture, NetFlow, session reconstruction, IOC extraction, and command-and-control server identification — recovering the complete history of adversarial communication.
Malware & Reverse Engineering
Static and dynamic analysis in sandbox, unpacking, deobfuscation, and TTP mapping against MITRE ATT&CK — deep understanding of what the adversary actually did in the environment.
Logs & Timeline
Log correlation from SIEM, EDR, IdP, and cloud to reconstruct the kill chain minute by minute — from initial access to exfiltration, with court-admissible evidence.
Chain of Custody
ISO/IEC 27037 procedures with SHA-256 hashing, digital seals, and auditable trail of every piece of evidence — from collection to court presentation.
Judicial Expert & Report
Signed expert report, technical court assistance, and specialized testimony — investigation that withstands cross-examination and supports legal accountability.
Frequently Asked Questions
What is Berghem's incident response time?
Does Berghem provide digital forensics?
Can Berghem handle ransomware incidents?
What happens after an incident is resolved?
Active incident?
If you are facing a security incident right now, contact us immediately to activate 24/7 emergency response.
Contact emergency response