Home/Services/Website Log Analysis & Forensics
security service

Website Log Analysis & Forensics

Website log analysis and forensics: find how attackers got in, what they took, and a defensible timeline for insurers and GDPR. Get a fixed investigation quote.

Manual, expert-ledEvidence-based findingsFree remediation retest

Website analysis and forensics answers the two questions every business asks after a breach: how did they get in, and what did they take. We reconstruct the attack from your server logs, files and database, so you are making decisions on evidence instead of guesswork.

Cleaning a hacked site removes the symptoms. Forensics tells you the cause and the scope. Without it you are patching a hole you cannot see, notifying customers on a hunch, and answering your insurer’s questions with “we think”. A proper investigation replaces all of that with a documented timeline: the entry point, the actions the attacker took, the data they reached, and the moment it started. That is the difference between recovering from an incident and merely surviving it, and it is the difference between telling your customers the truth and telling them a hopeful version of it.

What website analysis and forensics actually covers

This is investigative work, not a scan. An engineer reads the evidence your systems recorded, correlates it across sources, and builds a factual account of what happened. The goal is answers you can act on and defend, not a list of alerts.

Access and error log analysis across Apache, nginx and application logs
Timeline reconstruction from first intrusion to discovery
Identification of the exact entry point that was used
Assessment of what data was accessed, changed or exfiltrated
File modification and integrity comparison against a clean baseline
Malware and backdoor identification with indicators of compromise
Evidence preserved for insurers, legal counsel and regulators

Why guessing after a breach is expensive

The instinct after a hack is to clean up fast and move on. It is the wrong instinct. If you restore a backup without knowing the entry point, you often restore the vulnerability too, and the site is compromised again within days. If you do not know what data was touched, you either over-notify and alarm customers needlessly, or under-notify and breach your legal obligations. Both are costly. Forensics is what lets you respond once, correctly.

Reinfection is a symptom of skipping the investigation

A large share of the “we were hacked again” cases we see are not new attacks. They are the same attacker using the same backdoor or the same unpatched flaw, because the first cleanup treated the visible mess and never found the root cause. A forensic pass finds the door, not just the muddy footprints.

“How did they get in” is answerable

Servers record far more than people realise. The request that exploited a vulnerable plugin, the successful login from an unfamiliar address, the moment a web shell was uploaded and first called: these leave traces in the logs and on disk. With the right correlation, the entry point usually stops being a mystery.

How we investigate

Every investigation moves from evidence to conclusions in a defined order, so the findings hold up if an insurer, a regulator or a court ever examines them.

Preserve the evidence first

Before anything is changed, we capture the logs, file timestamps and relevant database state, because a hasty cleanup destroys the very evidence needed to understand the attack. Working from preserved copies means the investigation does not contaminate the scene, which matters if the findings feed a claim or a legal process.

Correlate the logs

We work through the access and error logs, pulling together attacker IP addresses, user-agent strings, request patterns and response codes. A spray of requests to a known plugin path, followed by a 200 on a file that should not exist, followed by POSTs to that file, tells a story. This is where a website forensic analysis earns its value: turning thousands of raw log lines into a clear sequence of what the attacker did and when.

Building the timeline

The correlated events become a timeline with timestamps: initial compromise, persistence established, actions taken, data reached, and the point of discovery. That timeline is the backbone of the report and the anchor for any breach-notification decision, because notification law turns on when you became aware and what was affected.

Examine the files and database

We compare the site’s files against a clean baseline to find what was added or modified, identify web shells and injected code, and check file modification times against the log timeline to confirm the sequence. The database is reviewed for injected content, tampered records, exported data and rogue administrator accounts. Together these show what the attacker changed and what they were able to reach.

Determine impact and root cause

The investigation ends with two conclusions stated plainly: how the attacker got in, and what data was exposed. From there we give you the specific fix for the entry point so the same route cannot be used again, which is the piece that stops the reinfection cycle. Root cause is not always a single flaw; sometimes it is a chain, such as a weak password that let an attacker in and an over-privileged account that let them reach the data. We report the whole chain, because fixing one link and missing another leaves the door ajar.

24/7
rapid triage for an active or fresh incident
Timeline
defensible sequence, not a guess about what happened
NDA
every investigation handled in strict confidence
Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

Where the evidence actually lives

People assume the trail is gone. Usually it is not, it is just scattered across sources nobody thought to protect. Part of the skill is knowing where to look and pulling those sources together before they age out.

Server and application logs

The web server access and error logs are the primary record, but the application layer often logs its own events too: WordPress security plugins, authentication logs, PHP error logs. Each holds a piece of the picture, and the useful window can be short because many hosts rotate logs after a few weeks, so acting early matters.

Firewall, CDN and hosting panel logs

If a web application firewall or a CDN sits in front of the site, it keeps its own request history, sometimes retained longer than the origin server’s. Hosting control panels record FTP and SSH sessions and file-manager activity. These often survive even when the site’s own logs have been tampered with, which is exactly why an attacker who wipes local logs can still be caught.

Backups as forensic snapshots

An old backup is a photograph of the site at a point in time. Comparing a pre-incident backup against the compromised site shows precisely which files changed, and lining several backups up narrows when the change happened. We use them as evidence, not just as a restore point.

External signals

Google Search Console manual actions, Safe Browsing warnings and blacklist entries carry timestamps and sometimes sample URLs, which help corroborate the internal timeline and confirm when the damage became publicly visible.

The questions a forensic report answers

A good investigation is judged by whether it lets you make decisions. Ours is built to answer the questions you will actually be asked.

What was taken, and do we have to notify?

We assess which records and data the attacker could reach and whether there is evidence of exfiltration. That assessment is what your legal counsel needs to decide on notification, and having it documented is far stronger than notifying on a worst-case assumption.

Is the attacker still inside?

Backdoors, scheduled tasks and rogue accounts let an attacker return after a cleanup. The investigation enumerates every persistence mechanism we find, so remediation removes all of them rather than leaving one quietly in place.

Can we prove what happened to our insurer?

Cyber-insurance claims and legal processes need evidence, not assertions. The preserved logs, the timeline and the indicators of compromise are assembled into a report written to support a claim or hand to counsel.

Forensics and your GDPR obligations

If personal data was involved, the investigation is not just useful, it is part of meeting the law.

Meeting the notification clock

GDPR Article 33 gives you 72 hours to notify the supervisory authority of a personal-data breach, and Article 34 governs notifying affected individuals. Both require you to describe the nature of the breach and the data involved. A forensic timeline and impact assessment is precisely the factual basis those notifications demand, and it protects you from either missing the obligation or over-reporting out of uncertainty.

Pricing

Forensic work is priced as an investigation package scoped by how much evidence there is and how deep you need to go. Rapid triage confirms whether and how you were breached; a full investigation delivers the complete timeline, impact assessment and report.

Package What’s included Response time Price
Rapid triage Single site, evidence preservation, log review to confirm compromise, entry point and immediate indicators of compromise Same or next business day from €450
Full investigation Complete log correlation, timeline, file and database forensics, impact assessment, root cause, written report 3–6 working days from €900
Breach & notification support Full investigation plus a GDPR-ready impact assessment and evidence pack for insurers, counsel or regulators Prioritised €1,500–€4,000
Emergency response Active incident, out-of-hours investigation and containment guidance alongside your team 24/7, hourly from €180/hr
Custom / complex Multiple sites, large log volumes or litigation-grade evidence handling, scoped after a call on scoping custom

Every package is fixed-price where scope allows, quoted after a free 20-minute call, with an NDA in place before any evidence changes hands. Get a fixed quote

FAQ

How much does website analysis and forensics cost?
Rapid triage to confirm and locate a breach starts from €450, and a full forensic investigation with a complete timeline and report starts from €900. The website analysis forensics cost depends on evidence volume and depth, and you get a fixed price after a free scoping call.
Can you actually tell how they got in?
In most cases, yes. Servers log far more than people expect, and by correlating access logs, file timestamps and database changes we can usually identify the exact entry point, whether it was a vulnerable plugin, a stolen credential or an exposed admin panel.
Will you also tell us what data was stolen?
We assess which data the attacker could reach and look for evidence of exfiltration, then state that plainly in the report. That impact assessment is what your legal team needs to make an informed notification decision rather than notifying on a worst-case guess.
We already cleaned the site. Can you still investigate?
Often yes, though the sooner we start the more evidence survives. A cleanup overwrites some traces, but logs, backups and file history frequently still hold enough to reconstruct the attack. Do not delete logs or backups, and contact us before overwriting anything else.
Do you help with GDPR breach notification?
Yes. The Breach and notification support package delivers a timeline and impact assessment built for GDPR Article 33 and 34, giving you the factual basis to notify the authority within 72 hours and to inform affected individuals if required.
How is this different from just cleaning the hacked site?
Cleanup removes the malware; forensics explains the cause and scope. Skipping the investigation is why so many sites are reinfected within days, because the entry point and any hidden backdoor were never found. Many clients pair the two, investigating first, then cleaning with full knowledge of what to remove.
Can the evidence be used for an insurance claim or legal case?
Yes. We preserve evidence before touching the system and document the chain of what we examined, so the report and indicators of compromise can support a cyber-insurance claim or be handed to legal counsel.
Is our data and the investigation kept confidential?
Always. Every investigation runs under an NDA agreed before evidence changes hands, findings are shared over secure channels, and access is limited to what the work requires.

Related services

Who needs this

Any business that has been hacked and needs to know how and how badly, teams facing a GDPR notification decision and unsure of the scope, sites that keep getting reinfected despite repeated cleanups, and anyone whose insurer or lawyer is asking for a documented account of what happened.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Website Log Analysis & Forensics"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.