SYLink
Free diagnostic
Computer Security Incident Response Team

SYLink CSIRT — our CERT, operated from France

An incident response team that picks up, triages and acts. Threat containment, eradication, recovery, forensics and regulatory support — around the clock, by French analysts, from Clermont-Ferrand and Marseille.

24/7
Hotline
< 15 min
Containment
< 5 min
MITRE detection
France
Operated from
You are under attack right now

Call us, don't fix it alone

Every minute counts, and the first moves decide what can still be saved. Our on-call team answers 24/7, weekends and public holidays included.

24/7 incident hotline
04 15 54 00 00Reporting form

The four immediate reflexes

  1. 1Do not power off affected machines: RAM holds the evidence and sometimes the decryption keys.
  2. 2Isolate from the network rather than shutting down — unplug the cable, disable Wi-Fi, leave the machine running.
  3. 3Do not pay and do not answer the attacker before you have technical and legal advice.
  4. 4Preserve logs: firewall, servers, mail, VPN. They often rotate away within days.
Our mission

What the SYLink CSIRT does

  • Triage

    Establish within minutes what is actually happening: affected scope, entry vector, compromised accounts, data at stake. A response only starts well if the diagnosis is right.

  • Contain

    Network isolation of infected endpoints and servers, disabling hijacked accounts, revoking sessions and tokens, cutting remote access. Stop the spread before repairing anything.

  • Eradicate and restore

    Removal of persistence, rebuilding of affected systems, restoration from verified clean backups, access hardening before returning to production. We never plug back in a door still open.

  • Document

    Timeline, evidence preserved to forensic standards, defensible incident report, regulatory notification file within 72 hours and support for internal and external communication.

Scope of response

Incidents we handle

  • Ransomware

    Encrypted servers or endpoints, double extortion with publication threats. Containment, strain identification, backup assessment, restoration and management of the attacker's pressure.

  • Account compromise and business email fraud

    Hijacked mailbox, hidden forwarding rules, impersonation of an executive or supplier. Regaining control of identities, access analysis and securing the payment chain.

  • Data leak

    Customer database published, exposed share, resale on a criminal forum. Authenticity check, exact scoping, regulatory notification and information of the individuals concerned.

  • Intrusion and silent exfiltration

    Stolen legitimate account, hijacked remote access, slow extraction below detection thresholds. Log hunting, weak-signal correlation, reconstruction of the attacker's path.

  • Denial of service

    Saturation of links or exposed applications. Upstream filtering, anti-DDoS activation, coordination with carrier and hosting provider to restore service.

  • Failure and insider sabotage

    Data destruction, conflictual departure, malicious action from a privileged account. Evidence freezing, attribution analysis and support for legal and disciplinary steps.

Typical sequence

What happens after your call

  1. T + 0

    Call intake and triage

    An analyst answers, opens the incident file and collects the first facts: what is observed, since when, on which systems. Preservation instructions are given immediately.

  2. T + 15 min

    First containment actions

    Network isolation of affected machines, cutting suspicious remote access, disabling hijacked accounts. Where our agents are already deployed, isolation is triggered remotely.

  3. T + 2 h

    Scoping

    Collection of logs and relevant memory and disk images, hunting for indicators of compromise across the estate, identification of the entry vector and of the data involved.

  4. D + 1

    Eradication and recovery

    Removal of the attacker's access, rebuilding of compromised systems, restoration from verified backups, hardening before return to production, reinforced monitoring.

  5. D + 5

    Report and follow-up

    Detailed incident report, timeline, evidence, root causes and a prioritised remediation plan. Regulatory notification file and, if you wish, support for filing a complaint and dealing with your insurer.

Resources mobilised

What the team relies on

The CSIRT does not arrive empty-handed: it works with the very components we operate daily for our customers, which lets it act on your information system from the first hour.

  • SYLink EDR — remote network isolation, indicator hunting across the estate, forensic collection
  • SYLink DPI probes — traffic reconstruction, identification of exfiltration and attacker callbacks
  • UniSOC — multi-source correlation and log hunting, on sovereign GPUs, with no outbound request
  • SYLink CTI — 12M+ indicators, 334k+ tracked CVEs, 100k+ YARA and Sigma rules to identify the strain
  • SYLink Leaks — immediate verification of what leaked and what already circulates on the darkweb
  • SYLink Honeypot — decoys deployed during the crisis to detect the attacker coming back
Framework and commitments

How we work

  • Availability

    • 24/7/365 on-call
    • Weekends and public holidays
    • Immediate call pickup
    • Remote and on-site response
  • Confidentiality

    • TLP protocol applied
    • No disclosure without consent
    • Analysis on French infrastructure
    • Nothing sent outside the EU
  • Evidence and compliance

    • Documented chain of custody
    • Defensible report
    • Regulatory notification within 72h
    • Support for complaint and insurer
  • After the incident

    • Prioritised remediation plan
    • Reinforced monitoring
    • Debrief with your teams
    • Crisis exercise on request
Two ways to reach us

Under contract or in emergency

  • Customer under supervision

    For organisations already equipped with our probes, agents or UniSOC supervision: the CSIRT knows your information system, has the telemetry and can act with no discovery phase.

    • Contractual response times
    • Telemetry already in place
    • Immediate remote isolation
    • Crisis exercises included
  • Emergency response

    You are not a customer and you are under attack: we also respond in emergency, with no technical prerequisite and an accelerated scoping phase from the very first call.

    • No prerequisite
    • Scoping from the call
    • Remote or on-site response
    • Formal response quotation

An incident under way?

Do not wait until you understand everything before calling: triage is part of our job, and the first hours decide the rest.