SYLink CSIRT — our CERT, operated from France
An incident response team that picks up, triages and acts. Threat containment, eradication, recovery, forensics and regulatory support — around the clock, by French analysts, from Clermont-Ferrand and Marseille.
Call us, don't fix it alone
Every minute counts, and the first moves decide what can still be saved. Our on-call team answers 24/7, weekends and public holidays included.
The four immediate reflexes
- 1Do not power off affected machines: RAM holds the evidence and sometimes the decryption keys.
- 2Isolate from the network rather than shutting down — unplug the cable, disable Wi-Fi, leave the machine running.
- 3Do not pay and do not answer the attacker before you have technical and legal advice.
- 4Preserve logs: firewall, servers, mail, VPN. They often rotate away within days.
What the SYLink CSIRT does
Triage
Establish within minutes what is actually happening: affected scope, entry vector, compromised accounts, data at stake. A response only starts well if the diagnosis is right.
Contain
Network isolation of infected endpoints and servers, disabling hijacked accounts, revoking sessions and tokens, cutting remote access. Stop the spread before repairing anything.
Eradicate and restore
Removal of persistence, rebuilding of affected systems, restoration from verified clean backups, access hardening before returning to production. We never plug back in a door still open.
Document
Timeline, evidence preserved to forensic standards, defensible incident report, regulatory notification file within 72 hours and support for internal and external communication.
Incidents we handle
Ransomware
Encrypted servers or endpoints, double extortion with publication threats. Containment, strain identification, backup assessment, restoration and management of the attacker's pressure.
Account compromise and business email fraud
Hijacked mailbox, hidden forwarding rules, impersonation of an executive or supplier. Regaining control of identities, access analysis and securing the payment chain.
Data leak
Customer database published, exposed share, resale on a criminal forum. Authenticity check, exact scoping, regulatory notification and information of the individuals concerned.
Intrusion and silent exfiltration
Stolen legitimate account, hijacked remote access, slow extraction below detection thresholds. Log hunting, weak-signal correlation, reconstruction of the attacker's path.
Denial of service
Saturation of links or exposed applications. Upstream filtering, anti-DDoS activation, coordination with carrier and hosting provider to restore service.
Failure and insider sabotage
Data destruction, conflictual departure, malicious action from a privileged account. Evidence freezing, attribution analysis and support for legal and disciplinary steps.
What happens after your call
- T + 0
Call intake and triage
An analyst answers, opens the incident file and collects the first facts: what is observed, since when, on which systems. Preservation instructions are given immediately.
- T + 15 min
First containment actions
Network isolation of affected machines, cutting suspicious remote access, disabling hijacked accounts. Where our agents are already deployed, isolation is triggered remotely.
- T + 2 h
Scoping
Collection of logs and relevant memory and disk images, hunting for indicators of compromise across the estate, identification of the entry vector and of the data involved.
- D + 1
Eradication and recovery
Removal of the attacker's access, rebuilding of compromised systems, restoration from verified backups, hardening before return to production, reinforced monitoring.
- D + 5
Report and follow-up
Detailed incident report, timeline, evidence, root causes and a prioritised remediation plan. Regulatory notification file and, if you wish, support for filing a complaint and dealing with your insurer.
What the team relies on
The CSIRT does not arrive empty-handed: it works with the very components we operate daily for our customers, which lets it act on your information system from the first hour.
- SYLink EDR — remote network isolation, indicator hunting across the estate, forensic collection
- SYLink DPI probes — traffic reconstruction, identification of exfiltration and attacker callbacks
- UniSOC — multi-source correlation and log hunting, on sovereign GPUs, with no outbound request
- SYLink CTI — 12M+ indicators, 334k+ tracked CVEs, 100k+ YARA and Sigma rules to identify the strain
- SYLink Leaks — immediate verification of what leaked and what already circulates on the darkweb
- SYLink Honeypot — decoys deployed during the crisis to detect the attacker coming back
How we work
Availability
- 24/7/365 on-call
- Weekends and public holidays
- Immediate call pickup
- Remote and on-site response
Confidentiality
- TLP protocol applied
- No disclosure without consent
- Analysis on French infrastructure
- Nothing sent outside the EU
Evidence and compliance
- Documented chain of custody
- Defensible report
- Regulatory notification within 72h
- Support for complaint and insurer
After the incident
- Prioritised remediation plan
- Reinforced monitoring
- Debrief with your teams
- Crisis exercise on request
Under contract or in emergency
Customer under supervision
For organisations already equipped with our probes, agents or UniSOC supervision: the CSIRT knows your information system, has the telemetry and can act with no discovery phase.
- Contractual response times
- Telemetry already in place
- Immediate remote isolation
- Crisis exercises included
Emergency response
You are not a customer and you are under attack: we also respond in emergency, with no technical prerequisite and an accelerated scoping phase from the very first call.
- No prerequisite
- Scoping from the call
- Remote or on-site response
- Formal response quotation
An incident under way?
Do not wait until you understand everything before calling: triage is part of our job, and the first hours decide the rest.
