A specialist DFIR firm built by senior practitioners who have spent two decades on the front line of incident response.
The leadership at Makkari has spent over twenty years leading and developing offensive and defensive teams across the UK and EU, on front-line ransomware engagements, state-aligned intrusions, and multi-national panel investigations.
We founded Makkari to deliver the standard every organisation deserves: a real answer, a real eviction, a real hardening plan. Not a boilerplate report, not a single-tool verdict, not a recommendation written to protect the firm's reputation.
We are transparent about what we deliver, and we do not bluff anything else. Where specialist capability is needed beyond DFIR, we route to named trusted partners.
Four lines we hold without exception.
Every critical finding is reproduced through an independent method. EDR, disk, memory, cloud logs all need to tell the same story. If they do not, we keep digging until they do.
The Makkari Forensics Engine is automation, not language modelling. Every conclusion is grounded in raw artefact, including the memory dump.
The single most important output of an IR engagement. We name the vector, the timeline, and the artefact that proves both. No "probable phish".
The practitioner who scopes the engagement is the practitioner who works it. No hand-off to a training pool, no silent subcontracting.
No sales engineers. No inherited juniors. Just the team.