Saltar al contenido
03 · SOC Gestionado03 · Managed SOC

Análisis Forense DigitalDigital Forensics

Adquisición, preservación, análisis e informe pericial.Acquisition, preservation, analysis and expert witness reporting.

ForenseForensics 3.2 · Gestión de Incidentes3.2 · Incident Management

¿Qué es este servicio?What is this service?

Es la adquisición, preservación y análisis de la evidencia digital de un equipo, un servidor, un teléfono o un entorno en la nube, con informe pericial al final. Cada paso queda registrado en una cadena de custodia que documenta quién tocó qué, cuándo y con qué herramienta.

The acquisition, preservation and analysis of digital evidence from a workstation, a server, a phone or a cloud environment, ending in an expert report. Every step is recorded in a chain of custody documenting who touched what, when and with which tool.

¿Para qué se usa?What is it used for?

Sirve para reconstruir qué pasó de verdad y para sostenerlo cuando alguien lo cuestione. La cadena de custodia no es burocracia: es lo único que separa una prueba admisible de un archivo que la contraparte tumba en dos minutos. Si el disco se copió sin bloqueador de escritura, sin hash de verificación y sin acta, el informe puede ser técnicamente impecable y jurídicamente inútil.

It reconstructs what actually happened and holds up when somebody challenges it. Chain of custody is not paperwork: it is the only thing separating admissible proof from a file the other side dismantles in two minutes. If the disk was copied without a write blocker, without a verification hash and without a signed record, the report can be technically flawless and legally worthless.

Qué beneficios traeBenefits it delivers

  • Determina el alcance real del compromiso: qué datos se tocaron, cuándo entraron y si siguen dentro.
  • La evidencia queda en condiciones de usarse en un proceso judicial, laboral o administrativo, y no solo interno.
  • Sostiene el reclamo al ciberseguro, que suele exigir informe forense independiente antes de pagar.
  • Separa el hecho de la suposición: en un fraude interno, la diferencia entre despedir y ser demandado por despido injustificado.
  • Establishes the real scope of the compromise: which data was touched, when they got in and whether they are still there.
  • Leaves the evidence fit for use in judicial, employment or administrative proceedings, not merely internal ones.
  • Supports the cyber insurance claim, which usually demands an independent forensic report before paying.
  • Separates fact from assumption: in internal fraud, the difference between dismissing someone and being sued for unfair dismissal.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No hay obligación legal de contratar un análisis forense en Costa Rica.
  • Si el incidente afectó datos personales, la Ley 8968 sigue vigente y PRODHAB es la autoridad: acreditar qué datos se vieron afectados y con qué alcance exige evidencia técnica, no una estimación.
  • Si el caso va a sede judicial o penal, la calidad de la cadena de custodia determina lo que el tribunal acepta.
  • There is no legal obligation to commission a forensic analysis in Costa Rica.
  • If the incident affected personal data, Law 8968 remains in force and PRODHAB is the authority: evidencing which data were affected and to what extent requires technical proof, not an estimate.
  • If the matter reaches court or criminal proceedings, the quality of the chain of custody determines what the court accepts.

InternacionalInternational

  • PCI-DSS exige investigación forense ante un compromiso confirmado de datos de tarjetas, y las marcas pueden exigir que la haga un investigador acreditado.
  • El RGPD obliga a documentar toda violación de seguridad de datos personales con sus efectos y medidas, y eso se sostiene con evidencia técnica.
  • ISO 27001 exige recopilar la evidencia de los incidentes de forma que sea admisible.
  • PCI-DSS requires forensic investigation on a confirmed compromise of cardholder data, and the card brands may require an accredited investigator to conduct it.
  • The GDPR requires documenting every personal data breach with its effects and measures, which rests on technical evidence.
  • ISO 27001 requires collecting incident evidence in a manner that renders it admissible.

Requisitos mínimosMinimum requirements

  • No apagar ni reinstalar nada antes de la adquisición. Es el error más común y borra la memoria volátil, que suele ser lo más valioso.
  • Autorización escrita del titular de los equipos y, si hay datos de empleados, revisión previa con el área legal.
  • Acceso físico o remoto con privilegios suficientes para adquirir imágenes completas, no solo archivos sueltos.
  • Definir desde el inicio si el caso puede terminar en tribunales, porque eso eleva el rigor de todo el procedimiento.
  • Not powering off or reinstalling anything before acquisition. It is the commonest mistake and it wipes volatile memory, often the most valuable material.
  • Written authorisation from the owner of the equipment and, where employee data is involved, prior review with legal.
  • Physical or remote access with privileges sufficient to acquire full images, not just individual files.
  • Deciding at the outset whether the matter could end in court, because that raises the rigour of the entire procedure.

Plazo típico de entregaTypical delivery time

2 a 8 semanas 2 to 8 weeks rango habitual del mercado usual market range

El rango habitual va de dos a ocho semanas. La adquisición es lo rápido: unas horas por equipo. Lo que estira el plazo es el volumen —analizar veinte estaciones no es lo mismo que analizar una— y el nivel de informe: un reporte técnico interno sale mucho antes que un dictamen pericial redactado para ser defendido ante un tribunal.

The usual range runs from two to eight weeks. Acquisition is the fast part: a few hours per machine. What stretches the timeline is volume — analysing twenty workstations is not the same as analysing one — and the level of reporting: an internal technical report lands far sooner than an expert opinion written to be defended in court.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

Cadena de custodiaChain of custody
El registro documentado de quién tuvo la evidencia en cada momento. Si se rompe, la prueba pierde valor legal. The documented record of who held the evidence at each moment. If it breaks, the proof loses legal weight.
Imagen forenseForensic image
Copia bit a bit del disco original, hecha sin alterarlo, sobre la que se trabaja para no tocar la fuente. A bit-for-bit copy of the original disk, made without altering it, worked on so the source is never touched.
HashHash
Huella matemática del archivo o del disco que demuestra que la copia es idéntica al original y no se modificó. A mathematical fingerprint of the file or disk proving the copy is identical to the original and was not altered.
Bloqueador de escrituraWrite blocker
Dispositivo que permite leer el disco original sin poder escribir sobre él ni por accidente. A device allowing the original disk to be read without any possibility of writing to it, even accidentally.
Línea de tiempoTimeline
La reconstrucción ordenada de los eventos con fecha y hora, que es donde aparece la historia completa del ataque. The ordered reconstruction of events with dates and times, where the full story of the attack emerges.