A specialist DFIR firm built by senior practitioners who have spent two decades on the front line of incident response.
The leadership at Makkari has spent over twenty years leading and developing offensive and defensive teams across the UK and EU, on front-line ransomware engagements, state-aligned intrusions, and multi-national panel investigations.
We founded Makkari to deliver the standard every organisation deserves: a real answer, a real eviction, a real hardening plan. Not a boilerplate report, not a single-tool verdict, not a recommendation written to protect the firm's reputation.
We are specialists in DFIR. For everything beyond it, we work with named, vetted partners and stay on the engagement as your single point of contact.
Four lines we hold without exception.
Every critical finding is reproduced through an independent method. EDR, disk, memory and cloud logs are reconciled until they tell the same story.
The Makkari Forensics Engine is automation, not language modelling. Every conclusion is grounded in raw artefact, including the memory dump.
The single most important output of an IR engagement. We name the entry vector, the timeline, and the artefact that proves both.
The practitioner who scopes the engagement is the practitioner who works it, from first call to final report. Continuous senior ownership, end to end.
Senior practitioners only. From the first call through to the final report.