Technical services

Digital forensics, cybersecurity and OT security

Find the digital evidence your case needs, prepare clear expert testimony, or uncover security weaknesses before attackers do. GDF brings experienced specialists and practical tools to the work.

Isolated test laptop connected to a network appliance.

Engagement paths

How we can help

Start with the help you need. Our specialists will work with you to define the scope, timing and next steps.

CISOs and IT managers

Validated attack paths and remediation evidence

Human-led penetration testing traces adversarial attack paths through internet-facing services, internal networks, identity systems, cloud control planes, applications and APIs. A practitioner reproduces each material finding before it enters the report.

Findings are ranked for material risk reduction rather than scanner severity alone. Vulnerability remediation guidance identifies the affected asset, exploit preconditions, business consequence, control owner, recommended fix and retest evidence. Incident readiness planning covers authority, escalation, preservation, communications and technical decision points.

SCADA and OT operators

Control-system evidence tied to operating consequence

Passive-first asset discovery establishes device, protocol, firmware, zone and communication context before any active step. Network segmentation validation checks whether documented IT/OT boundaries, remote-access paths and vendor connections behave as designed.

ICS security architecture review ties findings to safety, availability, recovery and process constraints. Operational consequence ranking puts credible process impact ahead of generic severity. NERC CIP compliance audit evidence is organized around the applicable requirement, source record, observed control, exception and remediation proof.

Professional boundary: GDF documents technical controls and audit evidence. GDF does not provide legal or regulatory advice or determine compliance status.

Service map

Select the service

Explore the services below, or get a free consultation to discuss your case, project or security concerns.

01

Digital Evidence & Litigation Support

Preserve source material, maintain a defensible chain of custody and explain the technical record for litigation, arbitration, regulatory proceedings or internal review. The work is organized for independent reproduction and expert challenge.

02

Cybersecurity & Adversarial Testing

Measure how realistic adversarial attack paths cross network, identity, cloud and application controls. Findings are validated by a practitioner, ranked for material risk reduction and paired with remediation and retest evidence.

03

OT, ICS & SCADA

Map assets and trust paths with a passive-first method, validate segmentation within operator-approved limits and rank findings by operational consequence. Safety, availability and recoverability remain part of the technical scope.

04

AI, Identity & Media

Examine whether a person, recording or digital artifact is consistent with its claimed source and history. Conclusions draw on provenance, metadata, signal characteristics and corroborating records, with confidence and limits stated in writing.

05

Incident Response & Resilience

Preserve volatile evidence while containment and recovery move forward. The response record documents entry, persistence, affected systems, potential data access, material decisions and the facts that remain unresolved.

06

Computer, Drive & Network Forensics

Dedicated routes restore the distinct source, acquisition and analysis questions that were previously collapsed into one broad computer, email and cloud page.

07

Hardware & AI Evidence

Specialized examinations address vehicle systems, embedded devices, integrated circuits and AI-generated or AI-mediated records without flattening their very different methods.

08

eDiscovery Workstreams

Each discovery phase has its own technical question, inputs and output. These pages let counsel and corporate teams enter at the workstream they actually need.

09

Specialized OT, ICS & SCADA

Industrial routes separate evidence reconstruction, architecture assessment, vulnerability operations and operator-approved testing while preserving the shared safety-first approach.

10

AI & Application Security

Architecture, source and adversarial testing pages distinguish design review from code analysis and full-system security validation.

11

Expert Testimony by Subject

Subject-specific expert work connects the technical record to a stated method, reproducible workpapers and testimony bounded by the available evidence.

12

Connected and Emerging Evidence

Dedicated routes address the acquisition, validation and interpretation limits of newer devices, transaction systems and media sources.

Engagement standards

A record that survives review.

Scope, source material, methods and limitations are written down so another qualified examiner can test the work.

  • Scope

    We agree on the question, the available evidence, authority to act and the conditions that would require a change in plan.

  • Examine

    Collection and testing follow the approved scope. Material observations are tied to their source, and open questions stay open until the evidence resolves them.

  • Report

    The final record separates observed facts from expert interpretation and states what the available material cannot establish.

Talk with an examiner

Discuss the matter and the next step.

Tell us what happened and what you need to find out. Speak with a GDF expert about how we can help.

24/7 hotline: 1-800-868-8189

Email collection, authentication and account takeover

  • Business Email Compromise Analysis: Someone used your business email or changed payment details? GDF analyzes Microsoft 365 email and account records to help explain what happened.
  • Email & Microsoft 365 Forensics: Remote Outlook and Microsoft 365 email collection, authentication, tracking and eDiscovery. Preserve email, cloud files and account activity with GDF.
  • Gmail & Google Workspace Forensics: Gmail and Google Workspace forensic collection, authentication and eDiscovery. Preserve email, Google Drive files and available activity logs with GDF.
  • Business Email Takeover Forensics: Hacked email account? GDF analyzes Microsoft 365 and Gmail compromise, phishing, data access, forwarding and persistence for counsel and responders.

GDF Core Analysis: departures and business separations

A flat-rate forensic examination for the agreed scope, with evidence preservation and an activity timeline that business leaders and counsel can understand.

  • Employee Exit Core Analysis: Did an employee take proprietary information? GDF Core Analysis preserves evidence and explains computer, email, cloud and AI activity at a flat rate.
  • Executive Departure Core Analysis: GDF Core Analysis examines executive computer, email, cloud and AI activity. Flat-rate forensic preservation and clear reporting for leadership.
  • Business Partner Separation Core Analysis: GDF Core Analysis preserves records when business partners separate. Flat-rate forensic examination of email, files, cloud storage and AI activity.

Get a free consultation

Continuous AI Penetration Testing

Explore continuous AI penetration testing for public-facing applications, services and APIs, with human-reviewed attack plans and validated findings.

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.