Digital Forensics & Incident Response (DFIR) Services India
24×7 Emergency Response | CERT-In Compliant | Legally Admissible Evidence | CERT-In Empanelled
India has witnessed a dramatic escalation in cybersecurity breaches over the last three years. The attack on AIIMS Delhi in November 2022 — which crippled hospital operations for weeks, compromised the records of millions of patients, and exposed critical gaps in healthcare cybersecurity — served as a watershed moment for Indian organisations. It demonstrated unambiguously that no sector is immune to sophisticated cyberattacks and that the difference between a contained incident and a catastrophic breach often comes down to the speed and quality of the incident response.
Today, under CERT-In Directions 2022, every Indian organisation that detects a cybersecurity incident — whether it is a ransomware attack, a data breach, an unauthorised access event, or a denial-of-service attack — must report it to CERT-In within six hours of detection. Failure to comply is a criminal offence under the Information Technology Act 2000.
MDIT Services is a CERT-In empanelled cybersecurity firm based in New Delhi. Our Digital Forensics and Incident Response (DFIR) team provides 24×7 emergency response capability for Indian organisations facing active cyberattacks. We combine deep technical forensic expertise — covering disk, network, mobile, cloud, memory, and email forensics — with a rapid, structured incident response process aligned to the NIST Incident Response Framework.
Our DFIR engagements produce evidence that is legally admissible under the Indian Evidence Act and the IT Act 2000, supporting criminal prosecutions, insurance claims, regulatory submissions, and civil litigation. Whether you are dealing with a ransomware attack at 2 AM or a suspected insider threat, MDIT is available around the clock to respond, investigate, and help you recover.
Digital Forensics Services
Disk & File System Forensics
Disk forensics is the foundation of most breach investigations. Our analysts create forensically sound bit-for-bit images of hard drives, SSDs, and storage arrays using write-blocked acquisition to preserve original evidence. We then analyse file systems — NTFS, ext4, APFS, FAT32 — to recover deleted files, examine file metadata, identify malware artefacts, reconstruct user activity timelines, and attribute actions to specific user accounts.
We use industry-standard tools including Autopsy, FTK (Forensic Toolkit), and X-Ways Forensics, and can recover evidence from physically damaged media in partnership with specialist data recovery labs.
Network Forensics
When a breach occurs, understanding how the attacker moved through the network is essential to containment and root cause analysis. Network forensics involves the capture and analysis of network traffic — PCAP files, NetFlow data, firewall logs, proxy logs, DNS query logs, and IDS/IPS alerts — to reconstruct the attacker’s path from initial access to their final objective.
Our network forensics capability identifies command-and-control (C2) communication channels, data exfiltration events (including volume, destination, and timing), lateral movement techniques, and the precise point of initial compromise. This intelligence is critical for both immediate remediation and long-term security improvement.
Mobile Device Forensics
With the growing use of smartphones and tablets in corporate environments, mobile devices are increasingly involved in both cyberattacks and insider threat cases. MDIT provides full mobile device forensics for iOS and Android devices, including physical extraction (when legally authorised), logical extraction, app data analysis, deleted message recovery, location history, and communication records.
Our mobile forensics work uses Cellebrite UFED, Magnet AXIOM, and Oxygen Forensic Detective — the same platforms used by law enforcement globally. All extractions are documented with full chain-of-custody records.
Cloud Forensics — AWS, Azure, GCP Log Analysis
As Indian organisations migrate to the cloud, attackers follow. Cloud forensics is now a mandatory capability for any serious incident response. MDIT’s cloud forensics team analyses:
- AWS: CloudTrail event logs, S3 access logs, VPC Flow Logs, GuardDuty findings, IAM audit trails, Lambda function logs
- Microsoft Azure: Azure Monitor logs, Azure Active Directory sign-in logs, Azure Defender alerts, Key Vault access logs, Storage account access logs
- Google Cloud Platform: Cloud Audit Logs, VPC Flow Logs, Cloud Armor logs, Identity and Access Management logs
We reconstruct the full cloud attack kill chain — from compromised IAM credentials to privilege escalation, lateral movement between services, and data exfiltration from cloud storage buckets.
Memory Forensics
Modern malware increasingly lives only in memory — leaving no artefacts on disk to evade traditional detection. Memory forensics involves capturing and analysing a system’s volatile RAM to identify running malicious processes, injected code, encryption keys held in memory, active network connections, and credentials being processed by running applications.
MDIT uses Volatility Framework and Rekall for memory analysis, enabling us to detect fileless malware, process hollowing, DLL injection, rootkit activity, and attacker tools that never touch the disk.
Email Forensics
Business email compromise (BEC), phishing attacks, and email-based malware delivery account for over 90% of initial attack vectors in India. Email forensics analyses email headers, SMTP relay paths, message authentication records (SPF, DKIM, DMARC), attachment metadata, and mailbox access logs to determine whether an account was compromised, whether phishing emails were delivered and read, and the true origin of malicious messages.
We work with Exchange Server, Microsoft 365, Google Workspace, and on-premises mail systems.
Incident Response Services
Emergency IR Retainer — 24×7 Hotline
An IR retainer is the most efficient way to ensure expert help is available the moment you need it. MDIT IR retainer clients receive a dedicated 24×7 hotline number, a guaranteed 2-hour initial response SLA, pre-incident preparation support (IR runbooks, contact trees, playbooks), and a fixed block of pre-purchased IR hours that can be used across the contract year.
Retainer clients also benefit from quarterly IR readiness reviews, tabletop exercises simulating realistic attack scenarios, and access to threat intelligence briefings relevant to their sector.
Ransomware Response
Ransomware is the most disruptive and financially damaging form of cyberattack in India today. When ransomware strikes, every minute of system downtime costs money, and every wrong decision can worsen the outcome. MDIT’s ransomware response protocol is immediate and decisive:
- Immediate triage: Identify the ransomware variant, assess scope of encryption, identify systems still unaffected
- Containment: Isolate affected segments, block C2 communication, prevent further spread
- Investigation: Identify initial access vector, establish attacker dwell time, determine scope of data exfiltration
- CERT-In notification: Prepare and submit mandatory incident report within 6-hour window
- Recovery: Restore systems from clean backups in order of business priority, verify integrity before reconnecting
- Eradication: Remove all malware, close exploited vulnerabilities, reset all potentially compromised credentials
- Post-incident: Deliver detailed forensic report, recommend security improvements
Data Breach Investigation
A confirmed or suspected data breach requires immediate, methodical investigation to determine what data was accessed, how it was accessed, whether it was exfiltrated, and who is potentially affected. This investigation is the foundation for regulatory notifications under CERT-In Directions 2022 and the Digital Personal Data Protection (DPDP) Act 2023.
MDIT’s breach investigation covers: identification of compromised systems and accounts, data classification analysis (what category of data was at risk), exfiltration confirmation or denial, attacker timeline reconstruction, and a legally robust breach report suitable for regulatory submission, insurance claims, and board presentation.
Insider Threat Investigation
Insider threats — whether malicious employees, negligent staff, or compromised accounts — are among the hardest incidents to detect and investigate. MDIT conducts confidential insider threat investigations that comply with Indian employment law and privacy regulations. We analyse endpoint activity, data access logs, email communications (where legally authorised), USB and removable media usage, and cloud storage activity to establish a factual evidence trail.
All insider threat investigations are conducted with strict confidentiality and in coordination with your HR and legal teams to ensure findings are admissible in employment tribunal proceedings or criminal prosecution.
Our Incident Response Process — NIST IR Framework
MDIT’s incident response process is structured around the NIST SP 800-61r2 Incident Response Framework, which defines six phases that ensure a systematic, repeatable, and legally defensible response to every incident.
- Preparation: Before an incident occurs, MDIT works with retainer clients to establish IR runbooks, communication trees, escalation procedures, evidence collection toolkits pre-deployed on critical systems, and relationships with law enforcement (CERT-In, cybercrime cells). Good preparation is the single most important factor in reducing incident impact.
- Detection & Analysis: Rapid identification and classification of the incident. MDIT analysts assess severity, scope, and type of incident within the first hour. The 6-hour CERT-In reporting clock starts at the point of detection.
- Containment: Immediate short-term containment (isolating affected systems) followed by long-term containment (securing the environment while investigation proceeds). Containment decisions are made with full awareness of business continuity needs.
- Eradication: Complete removal of all malware, attacker tools, and unauthorised access mechanisms. Closure of the initial access vector — patching the vulnerability, resetting compromised credentials, or blocking the attack path — is verified before recovery begins.
- Recovery: Systematic restoration of systems and services in priority order, with integrity verification at each stage. Recovery is monitored closely for any signs of re-infection or residual attacker presence.
- Post-Incident Activity (Lessons Learned): A structured post-incident review delivered within 10 business days of incident closure. This includes a full technical forensic report, executive summary, timeline reconstruction, root cause analysis, CERT-In final report, and specific security recommendations to prevent recurrence.
Legal Admissibility — IT Act 2000, Section 65B & Chain of Custody
In many DFIR engagements, the evidence collected will need to withstand scrutiny in court — whether in criminal prosecution, civil litigation, insurance arbitration, or regulatory proceedings. MDIT’s forensic processes are designed from the ground up for legal admissibility in the Indian legal system.
IT Act 2000
Under the Information Technology Act 2000, cybercrime offences including hacking (Section 66), data theft (Section 43A), and identity fraud (Section 66C) are prosecutable offences. MDIT’s forensic evidence collection meets the evidentiary standards required for prosecution under the IT Act, including proper documentation of the offence, system logs preserved in a legally defensible manner, and expert witness testimony if required.
Section 65B — Indian Evidence Act
Section 65B of the Indian Evidence Act 1872 governs the admissibility of electronic records as evidence in Indian courts. For electronic evidence to be admissible, a certificate under Section 65B must be produced by a responsible official of the organisation, attesting that the electronic record was produced by a computer that was regularly used, functioning properly at the time, and that the information was supplied in the ordinary course of activities.
MDIT assists your organisation in preparing Section 65B certificates and ensures that all digital evidence is collected, preserved, and documented in a manner that satisfies these statutory requirements.
Chain of Custody
Every piece of evidence collected during an MDIT investigation is subject to a strict chain-of-custody protocol:
- Evidence is catalogued with unique identifiers at the point of collection
- Cryptographic hash values (SHA-256) are recorded for all digital evidence to prove integrity
- Physical evidence is sealed in tamper-evident packaging
- A custody log records every person who handles the evidence, with timestamps
- Digital evidence copies (working copies) are made from original images to prevent contamination
- Storage of original evidence meets court-approved standards
Forensic Tools We Use
MDIT’s DFIR team uses the same tools trusted by law enforcement and intelligence agencies worldwide:
| Category | Tools |
|---|---|
| Disk Forensics | FTK (Forensic Toolkit), Autopsy, X-Ways Forensics, EnCase |
| Memory Forensics | Volatility Framework, Rekall, WinPmem |
| Network Forensics | Wireshark, NetworkMiner, Zeek/Bro, tcpdump, NetWitness |
| Mobile Forensics | Cellebrite UFED, Magnet AXIOM, Oxygen Forensic Detective |
| Malware Analysis | Cuckoo Sandbox, ANY.RUN, IDA Pro, Ghidra, FLARE VM |
| Cloud Forensics | AWS CloudTrail, Azure Monitor, GCP Audit Logs, Cloudtrail2SIEM, Invoke-LiveResponse |
| Log Analysis | Splunk, Elastic SIEM, LogRhythm, Microsoft Sentinel |
| Evidence Management | FTK Evidence Manager, CaseGuard, custom chain-of-custody documentation |
CERT-In Incident Reporting — We Handle It
CERT-In Directions 2022 (issued under Section 70B of the IT Act 2000) require Indian organisations to report cybersecurity incidents to CERT-In within 6 hours of detection. This is one of the strictest incident reporting timelines in the world. The types of incidents requiring mandatory reporting include:
- Targeted scanning or probing of critical networks/systems
- Compromise of critical systems/information
- Unauthorised access to IT systems/data
- Defacement of websites or intrusion into a website
- Malicious code attacks (ransomware, spyware, worms)
- Attacks on servers (web, mail, DNS) and network devices
- Identity theft, spoofing, and phishing attacks
- Data breach and data leakage
- Attacks on Internet of Things (IoT) devices
- Distributed Denial of Service (DDoS) attacks
MDIT handles CERT-In reporting as follows:
- Hour 1–2: Incident detected and confirmed. MDIT creates timestamped incident record and begins initial notification preparation.
- Hour 2–4: Initial technical assessment completed. Incident type, affected systems, and preliminary scope documented.
- Hour 4–5: CERT-In notification draft prepared in the prescribed format, reviewed with your designated CISO or compliance officer.
- Hour 5–6: Notification submitted to CERT-In via the official reporting portal (incident.cert-in.org.in) or email. Submission confirmation documented.
- Follow-up: MDIT provides updated reports to CERT-In as investigation progresses, per CERT-In requirements.
MDIT also assists with follow-up reporting, technical submissions to CERT-In investigators, and coordination with CERT-In during their investigation of significant national-level incidents.
Frequently Asked Questions — Digital Forensics & Incident Response India
What is digital forensics and incident response (DFIR)?
DFIR is the combined discipline of investigating cybersecurity incidents (incident response) and collecting, preserving, and analysing digital evidence to determine what happened, how it happened, and who was responsible. It is used for breach investigations, legal proceedings, and regulatory compliance.
How quickly can MDIT respond to a cyber incident?
Our IR team responds to emergency calls within 2 hours. Remote containment begins immediately. On-site deployment is available in Delhi NCR, Mumbai, Bangalore, Hyderabad, Pune, and Chennai within 4–12 hours depending on location.
Does MDIT handle CERT-In incident reporting?
Yes. We handle or support CERT-In mandatory incident reporting within the 6-hour window as required by CERT-In Directions 2022. We prepare the incident notification, document the timeline, and submit on your behalf with your authorisation.
Is digital forensic evidence collected by MDIT admissible in Indian courts?
Yes. All forensic evidence is collected following strict chain-of-custody protocols, hash-verified, and documented to meet the requirements of Section 65B of the Indian Evidence Act and the IT Act 2000, ensuring admissibility in Indian courts and regulatory proceedings.
What is an IR retainer and how does it work?
An IR retainer is a pre-arranged agreement that guarantees priority access to MDIT’s incident response team when an incident occurs. Retainer clients receive a dedicated IR hotline, guaranteed 2-hour response SLA, pre-incident preparation support, and a fixed number of annual IR hours included in the retainer fee.
Can you recover data from a ransomware attack without paying ransom?
In most cases, yes — if the organisation has clean offline or cloud backups. Our IR team specialises in restoring systems from backup, identifying and removing ransomware persistence mechanisms, and rebuilding compromised environments. We strongly advise against paying ransom, as it does not guarantee data recovery and funds criminal organisations.
What is cloud forensics and when is it needed?
Cloud forensics involves the investigation of security incidents that occur in cloud environments (AWS, Azure, GCP). It includes analysis of CloudTrail logs, Azure Monitor logs, GCP audit logs, storage access logs, IAM activity, and virtual machine forensics. It is needed when attackers compromise cloud accounts, exfiltrate data from cloud storage, or abuse cloud compute resources.
How long does a digital forensics investigation take?
A focused incident forensic investigation (one system, one incident) typically takes 3–7 business days. Complex enterprise breach investigations involving multiple systems, cloud environments, and insider threat components can take 3–6 weeks. We provide interim status reports throughout.
Emergency Contact — 24×7 Incident Response Hotline
Cyberattacks do not wait for business hours. MDIT’s emergency IR hotline is staffed by qualified security analysts every hour of every day. If you are experiencing an active incident — ransomware, breach, DDoS, or any other attack — call us immediately.
24×7 IR Emergency Hotline: +91 8130 479 555
Emergency Email: ir@mditservices.in (monitored 24×7)
- Initial response within 2 hours of first contact
- Remote containment begins immediately upon engagement
- CERT-In reporting managed by our team
- On-site deployment available: Delhi NCR, Mumbai, Bangalore, Hyderabad, Pune, Chennai
- Weekend and holiday coverage — no exceptions
Activate Emergency Response |
Enquire About IR Retainer
MDIT Services is a CERT-In empanelled cybersecurity organisation. New Delhi, India.
