SERVICE
OT Digital Forensics
Forensic investigation across the Windows-based systems, servers, and endpoints that support your industrial environment — establishing what happened, when, and how far it reached.
WHAT THIS SERVICE IS
OT Digital Forensics reconstructs what happened during a cyber incident across the systems that support industrial operations — engineering workstations, Windows-based SCADA/HMI infrastructure, historians, jump servers, and other supporting servers.
Our focus is the IT and Windows-based layer of the OT environment, where the majority of usable forensic evidence exists: logs, endpoint artifacts, and file system activity.
WHEN ORGANIZATIONS NEED IT
- Establishing root cause and timeline after a contained incident
- Determining scope — what was accessed, changed, or exfiltrated
- Investigating a suspicious change to engineering workstation configuration or project files
- Supporting recovery decisions with evidence of what is and isn't trustworthy to restore
WHAT OTR³ PROVIDES
- Evidence collection and preservation across engineering workstations, historians, jump servers, and supporting infrastructure
- Log analysis across endpoints and available network telemetry
- Timeline reconstruction of attacker activity
- Scope determination — what was affected, and what wasn't
- Findings presented in terms your engineering and leadership teams can act on
OT-SPECIFIC CONSIDERATIONS
Our forensic capability is strongest on Windows-based engineering workstations, HMIs, historians, and supporting servers — the layer where standard forensic methodology applies and produces reliable evidence.
Proprietary PLC and controller platforms have limited, vendor-specific logging and evidentiary capability. Where an investigation touches these platforms, we're clear about what can and cannot be forensically established, and coordinate with OEMs where appropriate rather than overstating what's recoverable.
ENGAGEMENT PROCESS
- 1
Preserve
We prioritize preserving volatile and at-risk evidence before it's lost to time or remediation activity.
- 2
Collect
We collect logs, images, and artifacts from the relevant engineering workstations, servers, and endpoints.
- 3
Analyze
We reconstruct the timeline of activity and determine scope of access or impact.
- 4
Report
Findings are documented clearly, distinguishing what's established from what remains uncertain.
DELIVERABLES
- Forensic timeline of the incident
- Scope-of-impact findings
- Evidence preservation for potential legal, insurance, or regulatory needs
- Recommendations feeding into recovery and hardening
RELATED SERVICES
OT Incident Response
Rapid containment and expert-led response to minimize impact and restore operations.
Learn MoreOT Ransomware Response & Recovery
Specialized recovery for OT environments. We restore systems safely and securely.
Learn MoreIndustrial Cyber Recovery
Full-scope recovery for industrial control systems following a cyber incident.
Learn MoreReady to talk to OTR³?
Active incident or planning ahead — reach out and we'll point you to the right engagement.
