Skip to content
FORTIS AEGIS ADVISORYCyber intelligence
Agentic forensic intelligence

Fortis Forensic Analyst

Specialized solution that automates validation, correlation and analysis of digital evidence to reconstruct incidents and evaluate possible attacks or compromises.

Fortis Aegis customers have on-demand access to the solution when they need to investigate signals, validate evidence, or understand the extent of a potential compromise.

01Access for Fortis Aegis customers
02Controlled and authorized execution
03Evidence-driven analysis
04Reasoned and auditable conclusions

Investigated ecosystem

Supported commercial platforms.

The solution correlates evidence from the platforms that support identities, code, infrastructure, workloads and security operations.

Amazon Web Services GitHub CrowdStrike OpenAI Docker HashiCorp Terraform

Logos identify compatibility and sources of evidence. Use does not imply partnership, certification, sponsorship or endorsement. Trademarks belong to their respective owners.

Everything the solution does

From raw evidence to reasoned reconstruction.

Each step preserves traceability, separates facts from hypotheses, and transforms scattered artifacts into a clear picture of the incident.

01 · Evidence

Forensic Preservation, Integrity and Chain of Custody

  • Inventories files, sources, accounts, regions, hosts, systems and time ranges relevant to the incident.
  • Computes SHA-256 hashes and generates deterministic manifests for integrity verification.
  • Preserves original evidence and separates raw material, working copies and derived artifacts.
  • Documents the origin, acquisition method, retention, pagination, truncation, coverage and limitations of each source.
  • Produces sanitized copies that preserve correlation between values without exposing original credentials or secrets.
  • Revalidates hashes, consistency and completeness before case consolidation and delivery.
02 · Timeline

Event Correlation and Attack Chain Reconstruction

  • Normalizes timestamps to UTC and the local time zone defined for the case.
  • Correlates identities, IPs, user-agents, sessions, commands, events, repositories, workflows, instances, volumes and containers.
  • Reconstructs credential lineage across IAM, STS, OIDC, PAT, OAuth, service accounts and human identities.
  • Structures the incident sequence from initial access through execution, escalation, persistence, collection, exfiltration and impact.
  • Distinguishes intent, attempt, execution, technical success and effectively proven impact.
  • Classifies each conclusion according to available evidence: confirmed, strongly correlated, provider-reported, unconfirmed or refuted.
03 · Cloud

Cloud Forensics and AWS Investigation

  • Analyzes CloudTrail, IAM, STS, SSM, EC2, EBS, S3, Lambda, EKS and other relevant telemetry sources.
  • Validates the account, region, asset, scope and forensic prerequisites before collection begins.
  • Works exclusively on instances, snapshots, volumes or restored copies authorized for analysis.
  • Performs remote collection using SSH over AWS Systems Manager Session Manager when applicable, without exposing additional ports.
  • Transfers artifacts with integrity verification between source and destination.
  • Executes batch analyses while maintaining independent logs, results and evidence chains for each asset.
04 · Supply Chain

Software Supply Chain and GitHub Forensics

  • Analyzes GitHub Audit Log, Actions, branches, pull requests, tags, commits, releases and pipeline artifacts.
  • Investigates unreachable Git objects, reflogs and alternative references when available.
  • Distinguishes the identity declared in commits from the operational identity proven by logs and authentication.
  • Correlates code changes with pipelines, builds, deployments, infrastructure and resources effectively reached.
  • Investigates PATs, OAuth Apps, GitHub Apps, OIDC, CircleCI, Atlantis, Terraform and other delivery-chain components.
  • Determines whether a change was merely submitted or was stored, executed, deployed and promoted to production.
05 · Workloads

Host, Container and Runtime Forensics

  • Examines systemd, cron, users, SSH, shell initialization, packages, cloud-init and management-agent artifacts.
  • Analyzes Docker and compatible runtimes, including images, layers, mounts, volumes, variables, entrypoints, processes and networking.
  • Identifies persistence mechanisms, anomalous execution and changes incompatible with the expected baseline.
  • Analyzes processes, connections, sockets, temporary files, logs and artifacts left by workloads.
  • Generates SBOMs and identifies vulnerabilities when tools such as Syft, Grype or Trivy are available.
  • Treats every collected artifact as potentially hostile content and avoids directly executing payloads found in the evidence.
06 · Threat Activity

Command and Control, Persistence and Exfiltration

  • Identifies infrastructure, patterns and indicators associated with Command and Control (C2).
  • Analyzes outbound connections, DNS, HTTP/S, sockets, beacons, callbacks and suspicious periodic communications.
  • Correlates processes, credentials, sessions and persistence mechanisms used to maintain access.
  • Investigates data staging, compression, aggregation, movement and transfer.
  • Determines whether there was only an exfiltration attempt or an effectively proven transfer.
  • Correlates source, destination, volume, protocol, period and artifacts associated with possible data egress.
07 · Recovery

Forensic Recovery and Artifact Reconstruction

  • Performs assisted recovery on snapshots, images, clones or unmounted volumes.
  • Locates and recovers logs, documents, scripts, local databases and other deleted artifacts.
  • Uses tools such as The Sleuth Kit, Autopsy and file-carving techniques when appropriate.
  • Reconstructs artifacts even when original metadata is no longer available.
  • Preserves hashes, origin, recovery method and context for each recovered item.
  • Documents limitations caused by block overwrites, TRIM, garbage collection or retention policies.
08 · Reporting

Evidence Analysis, Attribution Assessment and Incident Reporting

  • Consolidates technical evidence, correlated events and relevant indicators into a reproducible narrative.
  • Builds executive and technical timelines linking actions, identities, assets and impact.
  • Separates proven facts, analytical inferences and hypotheses that remain unconfirmed.
  • Documents Indicators of Compromise (IoCs), Tactics, Techniques and Procedures (TTPs), and relationships with MITRE ATT&CK when applicable.
  • Records evidence gaps, coverage limitations and issues that prevent definitive conclusions.
  • Produces technical and executive reports and forensic appendices suitable for incident response, audit, legal teams and stakeholders.

Sources and integrations

Evidence analyzed at different layers.

Fortis Forensic Analyst connects identity signals, cloud, code, pipelines, endpoints and containers to understand what happened, how it happened and what impact was proven.

Amazon Web Services

CloudTrail and CloudTrail Lake, IAM, STS, SSM, EC2/EBS, S3, Lambda, EKS, CloudWatch, Secrets Manager, KMS, cross-account identities, and restored EC2 copies.

GitHub / GitHub Enterprise

Audit Log, Actions, commits, branches, pull requests, bypasses, artifacts, PAT, OAuth Apps, GitHub Apps and automation identity.

CrowdStrike Falcon LogScale

CQL queries, event exports, groupings and pivots by host, user, IP, process and indicators.

CircleCI

Pipelines, jobs, artifacts, exposed variables, automation identity and correlation with changes in the repository.

HashiCorp Terraform / HCP Terraform

Plans, states, variables, executions, infrastructure changes and possible exposure of secrets in artifacts.

Docker

Images, layers, manifests, configurations, mounts, entrypoints, processes, networks and container artifacts.

OpenAI Codex

Agentic environment that applies the workflow, operates the authorized scripts and writes the reasoned analysis.

Auxiliary tools

Linux, Git, Atlantis, YARA, The Sleuth Kit, Autopsy, Plaso, Timesketch, Volatility, Velociraptor, Trivy, Syft and Grype can complement the analysis when installed and authorized.

Operational flow

An investigation traceable from start to finish.

Authorized sources and exports
Case Tracked Folder
Integrity and working copies
Normalization and correlation
Validation of hypotheses
Substantiated forensic report

Governance and autonomy

Customer control

The solution is a Skill developed for Codex/ChatGPT to support and orchestrate investigation, forensic analysis, evidence correlation and technical reporting processes.

Fortis Aegis provides the methodology, automation and operational intelligence embedded in the Skill, enabling teams to reduce incident response time, standardize investigations and accelerate the identification of the cause, extent and impact of a compromise.

The entire investigation process is conducted by the client's own team, within its environment and using its access credentials, tools, evidence and internal controls. Credentials, logs, source code, forensic artifacts, sensitive information and reports remain under the client's governance throughout the analysis, preserving privacy, confidentiality and trade secrets.

The initiative also seeks to make advanced incident response capabilities more accessible to startups, small and medium-sized businesses, and organizations without a dedicated forensic team or the financial resources to hire traditional DFIR and Incident Response services, allowing them to conduct structured investigations with greater autonomy and agility.

On-demand access

Assess a potential attack with evidence, context, and clarity.

Fortis Aegis customers can request the use of Fortis Forensic Analyst to support incident investigation, validate signs of compromise, and guide decisions based on what the evidence actually demonstrates.

Speak to an expert