hexmortem · 0x00400420confidentialv24.04 · sha 9f4e…a2c1pgp 0x783E 8C5A
LIVE · incident intake operational pgp 5421 993B … EAB8 0385 lat EU-SW · 42ms tz UTC+01 · AD
uptime 99.98% queue 3 active · 2 pending last note · 2026-05-30
← /usr/bin/services

0x02 · service brief

Exfiltration Scoping Audit

A bytes-on-wire reconstruction of what actually left the network, replacing hand-waved estimates with defensible volumetric and content findings. Built for matters where notification populations, regulatory fines, and indemnity limits turn on the precise scope of data egress.

pricefrom €22,000 / scope
turnaround2-4 weeks · regulator/notification deadlines respected
buyersCyber insurance carriers and DPOs whose notification obligations or claim…
Have an artefact in front of you? request scoping →

01what you get

02how to start

Reply with the artefact identifiers you have in hand (hashes, firmware version, advisory ID, or a description of the evidence bundle). We confirm authorisation and scope before any analysis begins. If a deadline is in play, name it — we scope depth against the deadline, not against an internal pipeline.

03scoping intake

Identify the breach window, the egress telemetry you have (full PCAP, proxy logs, netflow/IPFIX, cloud audit), the notification deadline driving the scope, and any leak-site or actor-claim references we should reconcile against.