hexmortem · 0x00400420confidentialv24.04 · sha 9f4e…a2c1pgp 0x783E 8C5A
LIVE · incident intake operational pgp 5421 993B … EAB8 0385 lat EU-SW · 42ms tz UTC+01 · AD
uptime 99.98% queue 3 active · 2 pending last note · 2026-05-30
← /usr/bin/services

0x01 · service brief

Cold-Case Reconstruction

A forensic rebuild of an incident 30 to 365 days after the fact, when first responders have demobilized and systems have been patched or restored. Designed for matters where the original timeline no longer holds up under regulatory or litigation scrutiny and the evidentiary record must be reconstituted from fragmented artifacts.

priceFrom €85,000
turnaround30-365 days post-incident · 4-12 weeks delivery
buyersBreach coaches and panel counsel facing a regulator, reinsurer, or plaintiff…
Have an artefact in front of you? request scoping →

01what you get

02how to start

Reply with the artefact identifiers you have in hand (hashes, firmware version, advisory ID, or a description of the evidence bundle). We confirm authorisation and scope before any analysis begins. If a deadline is in play, name it — we scope depth against the deadline, not against an internal pipeline.

03scoping intake

Tell us when the original incident occurred, what artefacts survive (memory captures, log fragments, restored backups, prior IR notes), the regulatory or litigation pressure driving the rebuild, and the date the reconstructed record needs to land.