What an IR engagement should deliver.

A real answer about how the actor got in. The actor out. Evidence that the path is closed. A hardening plan that stops it happening again.

That used to be the baseline. Increasingly, it is not. Memory captures get skipped. Initial foothold determination gets replaced with "probable phish". AI-generated narrative goes into final reports without anyone checking it. The actor walks back in weeks later, through the path that was never proven.

We are not here to dunk on the industry. We are here to deliver the standard that used to be assumed.

How we deliver it

Three things, in writing.

Twenty years. Zero re-breaches.

Across our team's two decades on the front line of incident response, no engagement has resulted in a re-breach. The Eviction Pledge is the standard the work already meets.

The Makkari Forensics Engine.

Five years in development. Not AI. Automation of the tooling that holds up. Cross-verified, hallucination-proof, reproducible. Memory captured every host.

Senior on the keyboard.

The practitioner who scopes the engagement is the practitioner who works it. No hand-off. No training pool. Same name on the call and the report.

Operating principles

Short list. Hard line.

01

Multi-source or it did not happen.

One vendor's view is an input, not a conclusion.

02

Reproducible by a second examiner.

If we cannot re-run it, we did not prove it.

03

AI assists. Humans sign.

Machine learning accelerates triage. It does not write reports or testify.

04

Memory captured every host.

The single source of truth since the last reboot. Never skipped.

05

Outcome over reputation.

We do not soften findings, bury root cause, or hedge to protect ourselves.

06

Court-admissible by default.

Chain of custody, tooling hashes, examiner notes, from day one.

Start the conversation

A senior practitioner. A defensible answer. A call we take.

Whether you are actively breached, preparing retained counsel, or scoping a retainer, we are listening.