Website Log Analysis & Forensics
Website log analysis and forensics: find how attackers got in, what they took, and a defensible timeline for insurers and GDPR. Get a fixed investigation quote.
Website analysis and forensics answers the two questions every business asks after a breach: how did they get in, and what did they take. We reconstruct the attack from your server logs, files and database, so you are making decisions on evidence instead of guesswork.
Cleaning a hacked site removes the symptoms. Forensics tells you the cause and the scope. Without it you are patching a hole you cannot see, notifying customers on a hunch, and answering your insurer’s questions with “we think”. A proper investigation replaces all of that with a documented timeline: the entry point, the actions the attacker took, the data they reached, and the moment it started. That is the difference between recovering from an incident and merely surviving it, and it is the difference between telling your customers the truth and telling them a hopeful version of it.
What website analysis and forensics actually covers
This is investigative work, not a scan. An engineer reads the evidence your systems recorded, correlates it across sources, and builds a factual account of what happened. The goal is answers you can act on and defend, not a list of alerts.
Why guessing after a breach is expensive
The instinct after a hack is to clean up fast and move on. It is the wrong instinct. If you restore a backup without knowing the entry point, you often restore the vulnerability too, and the site is compromised again within days. If you do not know what data was touched, you either over-notify and alarm customers needlessly, or under-notify and breach your legal obligations. Both are costly. Forensics is what lets you respond once, correctly.
Reinfection is a symptom of skipping the investigation
A large share of the “we were hacked again” cases we see are not new attacks. They are the same attacker using the same backdoor or the same unpatched flaw, because the first cleanup treated the visible mess and never found the root cause. A forensic pass finds the door, not just the muddy footprints.
“How did they get in” is answerable
Servers record far more than people realise. The request that exploited a vulnerable plugin, the successful login from an unfamiliar address, the moment a web shell was uploaded and first called: these leave traces in the logs and on disk. With the right correlation, the entry point usually stops being a mystery.
How we investigate
Every investigation moves from evidence to conclusions in a defined order, so the findings hold up if an insurer, a regulator or a court ever examines them.
Preserve the evidence first
Before anything is changed, we capture the logs, file timestamps and relevant database state, because a hasty cleanup destroys the very evidence needed to understand the attack. Working from preserved copies means the investigation does not contaminate the scene, which matters if the findings feed a claim or a legal process.
Correlate the logs
We work through the access and error logs, pulling together attacker IP addresses, user-agent strings, request patterns and response codes. A spray of requests to a known plugin path, followed by a 200 on a file that should not exist, followed by POSTs to that file, tells a story. This is where a website forensic analysis earns its value: turning thousands of raw log lines into a clear sequence of what the attacker did and when.
Building the timeline
The correlated events become a timeline with timestamps: initial compromise, persistence established, actions taken, data reached, and the point of discovery. That timeline is the backbone of the report and the anchor for any breach-notification decision, because notification law turns on when you became aware and what was affected.
Examine the files and database
We compare the site’s files against a clean baseline to find what was added or modified, identify web shells and injected code, and check file modification times against the log timeline to confirm the sequence. The database is reviewed for injected content, tampered records, exported data and rogue administrator accounts. Together these show what the attacker changed and what they were able to reach.
Determine impact and root cause
The investigation ends with two conclusions stated plainly: how the attacker got in, and what data was exposed. From there we give you the specific fix for the entry point so the same route cannot be used again, which is the piece that stops the reinfection cycle. Root cause is not always a single flaw; sometimes it is a chain, such as a weak password that let an attacker in and an over-privileged account that let them reach the data. We report the whole chain, because fixing one link and missing another leaves the door ajar.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
Where the evidence actually lives
People assume the trail is gone. Usually it is not, it is just scattered across sources nobody thought to protect. Part of the skill is knowing where to look and pulling those sources together before they age out.
Server and application logs
The web server access and error logs are the primary record, but the application layer often logs its own events too: WordPress security plugins, authentication logs, PHP error logs. Each holds a piece of the picture, and the useful window can be short because many hosts rotate logs after a few weeks, so acting early matters.
Firewall, CDN and hosting panel logs
If a web application firewall or a CDN sits in front of the site, it keeps its own request history, sometimes retained longer than the origin server’s. Hosting control panels record FTP and SSH sessions and file-manager activity. These often survive even when the site’s own logs have been tampered with, which is exactly why an attacker who wipes local logs can still be caught.
Backups as forensic snapshots
An old backup is a photograph of the site at a point in time. Comparing a pre-incident backup against the compromised site shows precisely which files changed, and lining several backups up narrows when the change happened. We use them as evidence, not just as a restore point.
External signals
Google Search Console manual actions, Safe Browsing warnings and blacklist entries carry timestamps and sometimes sample URLs, which help corroborate the internal timeline and confirm when the damage became publicly visible.
The questions a forensic report answers
A good investigation is judged by whether it lets you make decisions. Ours is built to answer the questions you will actually be asked.
What was taken, and do we have to notify?
We assess which records and data the attacker could reach and whether there is evidence of exfiltration. That assessment is what your legal counsel needs to decide on notification, and having it documented is far stronger than notifying on a worst-case assumption.
Is the attacker still inside?
Backdoors, scheduled tasks and rogue accounts let an attacker return after a cleanup. The investigation enumerates every persistence mechanism we find, so remediation removes all of them rather than leaving one quietly in place.
Can we prove what happened to our insurer?
Cyber-insurance claims and legal processes need evidence, not assertions. The preserved logs, the timeline and the indicators of compromise are assembled into a report written to support a claim or hand to counsel.
Forensics and your GDPR obligations
If personal data was involved, the investigation is not just useful, it is part of meeting the law.
Meeting the notification clock
GDPR Article 33 gives you 72 hours to notify the supervisory authority of a personal-data breach, and Article 34 governs notifying affected individuals. Both require you to describe the nature of the breach and the data involved. A forensic timeline and impact assessment is precisely the factual basis those notifications demand, and it protects you from either missing the obligation or over-reporting out of uncertainty.
Pricing
Forensic work is priced as an investigation package scoped by how much evidence there is and how deep you need to go. Rapid triage confirms whether and how you were breached; a full investigation delivers the complete timeline, impact assessment and report.
| Package | What’s included | Response time | Price |
|---|---|---|---|
| Rapid triage | Single site, evidence preservation, log review to confirm compromise, entry point and immediate indicators of compromise | Same or next business day | from €450 |
| Full investigation | Complete log correlation, timeline, file and database forensics, impact assessment, root cause, written report | 3–6 working days | from €900 |
| Breach & notification support | Full investigation plus a GDPR-ready impact assessment and evidence pack for insurers, counsel or regulators | Prioritised | €1,500–€4,000 |
| Emergency response | Active incident, out-of-hours investigation and containment guidance alongside your team | 24/7, hourly | from €180/hr |
| Custom / complex | Multiple sites, large log volumes or litigation-grade evidence handling, scoped after a call | on scoping | custom |
Every package is fixed-price where scope allows, quoted after a free 20-minute call, with an NDA in place before any evidence changes hands. Get a fixed quote
FAQ
How much does website analysis and forensics cost?
Can you actually tell how they got in?
Will you also tell us what data was stolen?
We already cleaned the site. Can you still investigate?
Do you help with GDPR breach notification?
How is this different from just cleaning the hacked site?
Can the evidence be used for an insurance claim or legal case?
Is our data and the investigation kept confidential?
Related services
Any business that has been hacked and needs to know how and how badly, teams facing a GDPR notification decision and unsure of the scope, sites that keep getting reinfected despite repeated cleanups, and anyone whose insurer or lawyer is asking for a documented account of what happened.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.