Forensic services

"" Overview and Key Features:

The Incident Response team offers digital forensic services for malicious computer activity. This service also facilitates access to third-party services if information security incidents need a more detailed analysis of changes made by malicious actors.

""  Getting Started:

Forensic services are provided for reported information security incidents. If you are experiencing an incident and you have not reported it, please follow the steps below.

  • Low severity incidents:

For low severity incidents, such as a compromised account or clicking a link in a phishing email, contact security.response@utoronto.ca.

  • Medium to critical severity incidents:

For information about medium to critical severity incidents, refer to the Incident Response Plan. If you are experiencing a medium to critical severity incident, complete the incident intake form.

""   Get Help:

If forensic services work is not already happening as part of a reported security incident, contact security.response@utoronto.ca.

Service Category: Information Security > Threat Detection and Response
Service run by: Office of the Chief Information Officer > Information Security
Service for: faculty, staff
Service Charges: none
Lifecycle Status: in operation
Standard Availability: on-demand
Scheduled Downtime: Scheduled As Needed