A cyber incident may be relevant to my investigation
Establish what is known, whether the activity is continuing and which systems, accounts and services may hold evidence. Containment protects operations but can also alter the record, so preserve and document deliberately.
Start with what needs doing now
Use this route to assess an active incident, preserve the most useful records and make bounded response decisions without assuming specialist support will arrive before evidence changes.
Move from the initial report to scope, preservation, event sequence, affected systems and careful attribution.
Reference CIM-000Assess urgencyIs the incident still happening?Distinguish continuing access, automated activity and completed events before deciding what must happen now.
Reference CIM-006Preserve firstWhat should be preserved immediately?Prioritise volatile logs, sessions, alerts, affected systems and provider records before response activity changes them.
Reference CIM-010Understand the evidence and the offender method
Use this route to understand what makes an event a cyber incident and see a separate insider operation create account, transfer and device evidence.
Separate suspicious activity, security alerts, confirmed events, impact and the evidential questions that follow.
Reference CIM-001Separate offender exampleDodgy Dave downloads the customer list and calls it working from homeSee legitimate notice-period access used for insider data theft, leaving account, transfer and device records.
Reference CIM-290Go directly to the issue you need to resolve
Map the incident across source systems before records are overwritten.
Reference CIM-009InterpretationDoes an indicator prove compromise?Use the match as a line of enquiry and test how it was generated.
Reference CIM-019TimelineHow should the incident sequence be built?Correlate sources while preserving their different clocks and meanings.
Reference CIM-280Containment recordWhat if the response changes the evidence?Record who acted, why, when, on what system and with what result.
Reference CIM-286Browse every Cyber incidents and offender methods guidance page
The complete reference library remains available when you need a narrower question.- A cyber incident may be relevant to my investigation - where do I start?
- What is a cyber incident?
- What exactly have I been given?
- Is this a source record, security alert, incident ticket, intelligence report or somebody’s summary?
- What could a cyber incident contribute to my investigation?
- Has an incident actually occurred, or is it only suspected?
- Is the incident still happening?
- What evidence may disappear quickly?
- Who controls the affected system?
- Which systems, accounts, devices and providers may hold evidence?
- What should be preserved immediately?
- What should not be altered?
- How should continuing harm and urgency be assessed?
- When is specialist cyber or forensic support required?
- What should I record during my first assessment?
- What is a security alert?
- Does a security alert prove an attack happened?
- What is a detection rule?
- What is an indicator of compromise?
- Does an indicator of compromise prove compromise?
- What is a false positive?
- What is a false negative?
- What is an anomaly?
- What is a security risk score?
- What is threat intelligence?
- Does a threat-intelligence match identify an offender?
- What underlying records should support an alert?
- What does the absence of an alert prove?
- Could security tooling have missed the activity?
- What is phishing?
- What can a phishing email actually prove?
- What is spear phishing?
- What is smishing?
- What is vishing?
- What is a malicious link?
- What is a fake login page?
- What is credential harvesting?
- What is consent phishing?
- What is business email compromise?
- What is impersonation fraud?
- Does clicking a phishing link prove compromise?
- Does entering credentials prove they were captured?
- What evidence may exist after a phishing incident?
- How should phishing infrastructure be preserved?
- What is credential theft?
- What is account takeover?
- How can credentials be stolen?
- What is password spraying?
- What is credential stuffing?
- What is a brute-force attack?
- What is an authentication attack?
- Does a successful login prove the password was known?
- Could a stolen session bypass the password?
- What is session hijacking?
- What is token theft?
- What is adversary-in-the-middle authentication theft?
- What is multi-factor authentication fatigue?
- What is SIM-swap-assisted account takeover?
- What evidence may show the point at which control changed?
- What access may remain after a password reset?
- What is malware?
- Does finding malware prove it was executed?
- What is a malicious file?
- What is a malware payload?
- What is a dropper?
- What is a downloader?
- What is a trojan?
- What is spyware?
- What is an information stealer?
- What is a keylogger?
- What is a backdoor?
- What is a bot?
- What is a rootkit?
- What is fileless malware?
- What is a malicious macro?
- What is a script-based attack?
- What evidence may show malware execution?
- What evidence may show malware persistence?
- What can antivirus detection prove?
- Could legitimate software be misidentified as malware?
- What is a remote-access tool?
- Can legitimate remote-support software be used maliciously?
- What is remote desktop access?
- What is remote monitoring and management software?
- What is a web shell?
- What is remote command execution?
- What does an interactive remote session prove?
- Could an attacker control a device without physically possessing it?
- What logs may show remote access?
- What evidence may identify the remote controller?
- What should be preserved before terminating a remote session?
- Could containment destroy remote-session evidence?
- What is initial access?
- What is a vulnerability?
- What is exploitation?
- What is an exploit?
- What is a zero-day vulnerability?
- Does a vulnerable system prove it was exploited?
- What is an exposed service?
- What is an unpatched system?
- What is a drive-by compromise?
- What is malicious advertising?
- What is exploitation of a public-facing application?
- What evidence may show the point of entry?
- Could an incident have several possible entry routes?
- How should uncertainty about the initial access route be reported?
- What is persistence?
- What is privilege escalation?
- What is administrator access?
- How can a new user account provide persistence?
- How can a scheduled task provide persistence?
- How can a system service provide persistence?
- What is a malicious startup item?
- How can an authentication token provide persistence?
- How can a browser extension provide persistence?
- What is an application-consent foothold?
- How can a web shell provide persistence?
- Does the presence of persistence prove it was used?
- What evidence may show when persistence was created?
- What should be preserved before persistence is removed?
- What is system discovery?
- What is network discovery?
- What is account discovery?
- What is service discovery?
- What is permission and group discovery?
- What is security-software discovery?
- What is file and directory discovery?
- Does reconnaissance prove the next stage of an attack occurred?
- What evidence may show internal reconnaissance?
- Could legitimate administration look like reconnaissance?
- What can the sequence of discovery activity tell an investigator?
- What is lateral movement?
- Does access to one system prove access to the wider network?
- What is credential reuse?
- What is pass-the-hash?
- What is remote-service execution?
- What is network-share access?
- What is account pivoting?
- What evidence may show movement between systems?
- Could legitimate administration look like lateral movement?
- How should linked events across several systems be correlated?
- Does use of an administrator account prove the administrator was responsible?
- How should the extent of lateral movement be reported?
- What is command and control?
- What is beaconing?
- Does beaconing prove an attacker was actively controlling the device?
- What is a command-and-control server?
- What is domain-based command and control?
- What is IP-based command and control?
- What is command and control over a legitimate cloud service?
- What is command and control over web traffic?
- What is command and control over DNS?
- What is a dead-drop resolver?
- What evidence may show command tasking?
- What evidence may show interactive control?
- Could legitimate administration look like command and control?
- How should command-and-control evidence be reported?
- What is data collection?
- What is data staging?
- What is exfiltration?
- Does file access prove data theft?
- Does creating an archive prove data was exfiltrated?
- What is cloud-based exfiltration?
- What is exfiltration over email or messaging?
- What is exfiltration over a remote-access session?
- What is exfiltration over removable media?
- What is exfiltration over DNS?
- What is encrypted exfiltration?
- What evidence may show that a transfer completed?
- What evidence may identify the data that left?
- Does outbound traffic volume prove data theft?
- How should suspected exfiltration be reported?
- What is ransomware?
- Does ransomware always encrypt files?
- What is double extortion?
- What is a ransom note?
- Does a ransom note prove who carried out the attack?
- What evidence may show file encryption?
- Does encryption prove data was stolen?
- What evidence may show the sequence of a ransomware incident?
- What evidence may show backup targeting?
- What evidence may show deliberate disruption?
- What should be preserved immediately in a ransomware incident?
- Should systems be rebuilt immediately after ransomware?
- Can backups be trusted after ransomware?
- What is a decryptor?
- Does successful decryption prove the incident is over?
- Should an organisation pay a ransomware demand?
- Does payment prove the payer accepted the offender’s claims?
- What evidence should be preserved from ransomware negotiations?
- What can a cryptocurrency payment prove?
- Does receiving a decryptor prove the sender caused the encryption?
- What is a ransomware leak site?
- Does removal from a leak site prove the data was deleted?
- How should ransomware attribution be approached?
- What should a final ransomware assessment distinguish?
- What is a denial-of-service attack?
- What is a distributed denial-of-service attack?
- What is a traffic-flood attack?
- What is an application-layer denial-of-service attack?
- What is reflection and amplification?
- What is a botnet-driven denial-of-service attack?
- What is resource exhaustion?
- Does a traffic spike prove an attack?
- Could a denial-of-service attack come from inside the organisation?
- What evidence may show deliberate service disruption?
- How should provider mitigation records be used?
- How should denial-of-service impact be reported?
- What is a web application attack?
- What is web scanning?
- What is directory traversal?
- What is SQL injection?
- What is cross-site scripting?
- What is command injection?
- What is file upload abuse?
- What is web-shell deployment?
- What is authentication bypass in a web application?
- What is business-logic abuse?
- How should web-attack evidence be reported?
- What is defence evasion?
- What is anti-forensics?
- What is log clearing?
- Does a missing log prove evidence was deleted?
- What is timestamp manipulation?
- What is secure deletion?
- What is data destruction?
- What is a wiper?
- What is evidence tampering?
- Could legitimate cleanup look like anti-forensics?
- What should be preserved before destructive activity is contained?
- How should destructive and anti-forensic activity be reported?
- What is insider misuse?
- Does authorised access mean the activity was legitimate?
- Does an employee account identify the employee who acted?
- What is misuse of privileged access?
- What is unauthorised data access by an insider?
- Does copying data prove malicious intent?
- What is unauthorised disclosure?
- What is insider sabotage?
- Could an insider be coerced or manipulated?
- What is account sharing?
- What is post-employment access?
- Could careless behaviour look like malicious insider activity?
- What evidence may support insider attribution?
- How should suspected insider misuse be reported?
- What is attacker infrastructure?
- What is bulletproof hosting?
- What is an initial-access broker?
- What is a proxy or relay used by an offender?
- What is a residential proxy network?
- What is a compromised website used as infrastructure?
- What is infrastructure rotation?
- What is criminal infrastructure-as-a-service?
- What evidence may identify who controlled attacker infrastructure?
- How should attacker infrastructure be reported?
- What is a supply-chain compromise?
- Does a signed software update prove the software was safe?
- What is a compromised software update?
- What is managed-service-provider compromise?
- What is abuse of a remote-management platform?
- What does “living off the land” mean?
- Does use of an administrative tool prove malicious activity?
- What is abuse of a trusted cloud service?
- What is abuse of single sign-on or identity federation?
- What is supply-chain dependency abuse?
- What evidence may show abuse of a trusted service?
- How should supply-chain and trusted-service incidents be reported?
- What is cryptomining abuse?
- What is cryptojacking?
- Does high CPU or GPU use prove cryptomining?
- What is unauthorised cloud-resource abuse?
- What is resource hijacking?
- What is automated offender activity?
- What is a bot?
- What is automated account creation?
- What is automated credential testing?
- What evidence may show automation rather than manual activity?
- How should cryptomining and automated abuse be reported?
- What does technical attribution actually mean?
- What is personal attribution?
- How should an incident timeline be built?
- How should uncertain findings be expressed?
- What should be preserved before contacting a provider?
- What should an investigator ask a provider for?
- Does a provider record prove who performed the action?
- How should preservation requests be prioritised?
- What should be recorded when containment changes the evidence?
- When should specialist support be requested?
- How should technical findings be converted into investigative actions?
- What should the final cyber-incident report achieve?
- Dodgy Dave downloads the customer list and calls it working from home