Cybersnap.io Module · Deep & Forensic Intelligence

Find what happened before you decide what comes back.

When Quick Scan flags suspicion, Deep & Forensic Intelligence takes over. Deeper scanning, forensic timeline correlation, and persistence investigation across snapshot history, so the recovery decision accounts for what happened before the visible point of compromise.

Deep Scan · Timeline correlation · Persistence investigation · Slow-Moving Attack detection
Quick Scan alone

Breadth, but not depth.

Quick Scan is built for fast triage across the environment. It tells you where to look next, but it is not built to answer harder questions: how far back does this go, did the attacker sit quietly before the visible event, and which artifacts actually prove it.

With Deep & Forensic Intelligence

A timeline, not a guess.

Deep & Forensic Intelligence investigates the candidates Quick Scan flags, builds a timeline of findings across snapshots, and looks for the slow, gradual, or dormant activity that a single-point scan would miss, before the recovery decision is made.

Deep Scan. Timeline correlation. Forensic investigation.

Deep & Forensic Intelligence enters when Quick Scan indicates suspicion. It builds the evidence Quick Scan cannot, then feeds it back into the same recovery decision.

01 / DEEP SCAN
Targeted
Beyond Quick Scan

Deep Scan

Focused, deeper scanning of the specific points, systems, and artifacts that require more than Quick Scan can give. Where Quick Scan triages, Deep Scan investigates: the files, scripts, and artifacts behind a suspicious finding.

Scan depth
artifacts scripts systems files
02 / TIMELINE CORRELATION
Cross-snapshot
Bounding the incident

Timeline Correlation

Compares findings and changes across snapshots along the timeline to bound the incident and trace how the compromise progressed, workload by workload, snapshot by snapshot.

Snapshot history · 14 points
03 / FORENSIC INVESTIGATION
Historical
Slow-Moving Attack detection

Forensic Investigation

Investigates historical patterns and Slow-Moving Attack behavior to identify activity that began before the visible point of compromise, gradual, dormant, or staged intrusions that a single scan would not surface.

Historical trace

Deeper evidence. The same three verdicts.

Deep & Forensic Intelligence does not produce a separate output. Its findings feed directly into the recovery verdict: safe to resume, requires investigation, or unsafe to resume.

Safe to resume

No historical signal

Deep Scan and timeline correlation found no earlier compromise. The candidate holds.

Requires investigation

Slow-moving pattern

Gradual or dormant activity detected earlier in the timeline. Recommends a wider investigation window.

Unsafe to resume

Persistence found

Forensic evidence shows compromise began before the visible event. This candidate is out.

See Deep & Forensic Intelligence on your evidence.

Book a demo and we will walk through Deep Scan, timeline correlation, and forensic investigation against a real recovery scenario.