Immediate response — this page is written to be used, not read

Emergency: the first hour

917-217-7975

Scoping call, free. Emergency mobilisation, $6,000 fixed, credited in full against whatever follows.

No staffed hours and no published response time, because I will not promise one I cannot staff. I answer when I can, and a no comes straight away rather than being held.

If you do nothing else here, do the six steps below. They are the same whether or not you call an examiner. Most avoidable loss comes from containing and destroying in the same motion.

Six things to do first, in this order

  1. Do not re-image, rebuild, “clean” or restore over an affected system. It is the most complete destruction of evidence available tonight. If a system must be rebuilt to keep trading, image it first, or rebuild onto new hardware and set the original aside, powered down and labelled.
  2. Do not reboot. Isolate instead. Pull the cable, shut the switch port, or use your EDR’s host isolation; if that triggers automatic remediation, switch it off. Leave the machine powered on and unlocked, and power off only if you cannot isolate: memory dies with the power. Before powering off an encrypted machine, check the recovery key is escrowed; without it the disk is ciphertext.
  3. Do not reflexively pull a domain controller, storage head, industrial controller or clinical device off the network. Take the order from someone who knows what depends on what, and write down what was decided and why.
  4. Suspend backup retention, expiry, garbage collection and replication now. Do not mount or restore until someone has established whether the backup system itself is compromised.
  5. Preserve the logs that expire, today. Raise local log sizes first, then export the relevant window out of the affected tenant. Turning auditing on tonight logs forward only. It recovers nothing.
  6. Start a log at minute one. UTC timestamps, who did what, on which system, why. Include the reboots and the mistakes. Move it off the email and chat you think may be compromised.

Retention clocks running now

As published by Microsoft, current at the date on this page. Defaults, not your tenant. Check yours.
Log source Default retention What this does not establish
Microsoft 365 Audit, Standard 180 days
records since 2023-10-17
Not who was at the keyboard; nothing before the earliest surviving record.
MailItemsAccessed Premium licence only Never licensed, never recoverable. Silence is not evidence nothing was read.
Exchange mailbox audit 90 days Actions on the mailbox, not content, not the person behind the session.
Entra ID sign-in logs 7 days free
30 days P1 / P2
An address is not a location; an account is not a person.

Exporting that window is the only step here that cannot be done later.

Then find your situation

If two apply, do both.

Ransomware

  1. Isolate in one coordinated sweep, not machine by machine.
  2. Preserve the note, its filename, and a sample of encrypted files with their extensions.
  3. Keep one fully encrypted machine untouched as the reference.
  4. Suspend tonight’s patching, imaging, backup expiry and log rotation.
  5. Do not delete the note, rename or “try” encrypted files, run a full anti-virus clean, or plug a technician’s USB drive into anything.

I do not advise on paying, do not negotiate, and will not contact a threat actor.

Fraudulent wire, or a compromised mailbox

  1. Call the originating bank’s fraud desk by phone within the hour for a recall or hold, and the receiving bank if you can identify it: the money clock is shorter than the forensic clock.
  2. File at ic3.gov immediately. Do not work out first whether you qualify.
  3. Capture inbox and transport rules before deleting any, including blank- or single-character-named ones, plus forwarding addresses at mailbox and tenant level, delegate permissions, registered MFA methods, OAuth consents and devices.
  4. Revoke sessions and tokens, remove attacker-registered MFA methods and app passwords, then reset the password, in that order. A reset alone does not evict an attacker holding a valid refresh token.
  5. Sweep every mailbox, not only the one somebody noticed.
  6. Do not delete the fraudulent emails. Preserve full headers, not forwarded copies.
  7. Have accounts payable verify every pending payment-detail change by calling a number you already held, never one from the email.

Departing employee

  1. Get the laptop out of the return-and-reimage queue. Physically out, labelled, logged.
  2. Do not boot it. Booting alters timestamps and can trigger a cloud sync or MDM wipe.
  3. Hold the mailbox, the cloud drive and the home directory, before offboarding scripts delete them.
  4. Never log into the individual’s personal email, cloud account or device, even from a session already open on the company laptop. It carries real legal exposure.
  5. Do not tip off the subject: an abrupt account disable, a device recall, a new DLP block, a conspicuous meeting.

When and how the individual is told depends on the employment agreement and applicable law — counsel’s decision, not IT’s.

Lost or stolen device

  1. Document the encryption state from the console before you send the wipe.
  2. Record the identifiers, last check-in, reported location, compliance state, and what was stored locally as against reachable only through a session.
  3. Revoke sessions, tokens and device trust.
  4. Record whether the wipe was queued, acknowledged or completed, and treat an unacknowledged wipe as a device still at large.
  5. File the police report and keep the report number.

Under a litigation hold nothing is wiped until counsel says so.

What the first call costs

The scoping call is free, up to 45 minutes — including the one that ends with me saying the data cannot answer your question, or that you do not need a forensic examiner. If a written preservation instruction is needed, you get one out of it.

Emergency mobilisation is $6,000, a fixed time-boxed first block with the out-of-hours uplift already in it. You end up holding a preservation direction, volatile and triage collection from up to five systems, a written preliminary position, and a scoped proposal with a ceiling. All of it is credited against whatever follows. Card, because a bank transfer does not clear at 02:00.

Conflicts are checked against the named parties at once. Nothing is touched before that clears and the engagement letter is signed; pay earlier and the payment is an offer, held unapplied and refunded in full if I cannot act. If a conflict surfaces later I withdraw, return or destroy the material on your instruction, and refund the unearned balance.

What I will not do, including at 02:00

  1. Take a fee that depends on what I find, on the outcome, or on which side retains me.
  2. Take or pay a referral fee, in either direction.
  3. Take a vendor commission, or sell you the remediation I was paid to investigate.
  4. Advise on paying a ransom, negotiate, or make contact with a threat actor.
  5. Touch a device, mailbox or account without documented authority from someone entitled to give it, whatever the story about ownership.
  6. Opine on who was at the keyboard from device evidence alone. A device is not a person.
  7. Opine that a party intended to destroy evidence. I report what existed, what was deleted, when, by what mechanism, and whether it survives elsewhere. Intent is for the court.
  8. Take a matter I cannot finish inside your deadline. You hear that on the first call.
  9. Take a matter requiring a certification, licence or qualification I do not hold.
  10. Promise a finding, a recovered file, an unlocked handset, or that anything I produce will be admitted.

Who you are calling

Wirewalk Forensics and Security is a digital forensics, incident response and litigation support practice in the New York area. I work either side at the same published rate.

Where a matter requires a certified examiner, an accredited laboratory, or a qualification I do not hold, that is stated in the engagement letter and satisfied before work begins, or the matter is declined. Where a venue regulates this work under a private-investigator or comparable licence, I check the position for your venue and take the matter only where that licence is held, or the work is performed under someone who holds it. Enterprise-scale, multi-jurisdiction response belongs with the panel consultancies.

Ring me and I will tell you whether this is even a forensics problem: 917-217-7975.

Document WW-F-002, version 1.0. Issued 2026-09-11, revised 2026-09-11. Retention figures and IC3 conditions change — check yours. If a figure here has moved, tell me and I will revise it.