Cyber Incidents & Offender Methods¶
290 investigator questions.
Use the list below or search the complete library.
- A cyber incident may be relevant to my investigation — where do I start?
- What is a cyber incident?
- What exactly have I been given?
- Is this a source record, security alert, incident ticket, intelligence report or somebody’s summary?
- What could a cyber incident contribute to my investigation?
- Has an incident actually occurred, or is it only suspected?
- Is the incident still happening?
- What evidence may disappear quickly?
- Who controls the affected system?
- Which systems, accounts, devices and providers may hold evidence?
- What should be preserved immediately?
- What should not be altered?
- How should continuing harm and urgency be assessed?
- When is specialist cyber or forensic support required?
- What should I record during my first assessment?
- What is a security alert?
- Does a security alert prove an attack happened?
- What is a detection rule?
- What is an indicator of compromise?
- Does an indicator of compromise prove compromise?
- What is a false positive?
- What is a false negative?
- What is an anomaly?
- What is a security risk score?
- What is threat intelligence?
- Does a threat-intelligence match identify an offender?
- What underlying records should support an alert?
- What does the absence of an alert prove?
- Could security tooling have missed the activity?
- What is phishing?
- What can a phishing email actually prove?
- What is spear phishing?
- What is smishing?
- What is vishing?
- What is a malicious link?
- What is a fake login page?
- What is credential harvesting?
- What is consent phishing?
- What is business email compromise?
- What is impersonation fraud?
- Does clicking a phishing link prove compromise?
- Does entering credentials prove they were captured?
- What evidence may exist after a phishing incident?
- How should phishing infrastructure be preserved?
- What is credential theft?
- What is account takeover?
- How can credentials be stolen?
- What is password spraying?
- What is credential stuffing?
- What is a brute-force attack?
- What is an authentication attack?
- Does a successful login prove the password was known?
- Could a stolen session bypass the password?
- What is session hijacking?
- What is token theft?
- What is adversary-in-the-middle authentication theft?
- What is multi-factor authentication fatigue?
- What is SIM-swap-assisted account takeover?
- What evidence may show the point at which control changed?
- What access may remain after a password reset?
- What is malware?
- Does finding malware prove it was executed?
- What is a malicious file?
- What is a malware payload?
- What is a dropper?
- What is a downloader?
- What is a trojan?
- What is spyware?
- What is an information stealer?
- What is a keylogger?
- What is a backdoor?
- What is a bot?
- What is a rootkit?
- What is fileless malware?
- What is a malicious macro?
- What is a script-based attack?
- What evidence may show malware execution?
- What evidence may show malware persistence?
- What can antivirus detection prove?
- Could legitimate software be misidentified as malware?
- What is a remote-access tool?
- Can legitimate remote-support software be used maliciously?
- What is remote desktop access?
- What is remote monitoring and management software?
- What is a web shell?
- What is remote command execution?
- What does an interactive remote session prove?
- Could an attacker control a device without physically possessing it?
- What logs may show remote access?
- What evidence may identify the remote controller?
- What should be preserved before terminating a remote session?
- Could containment destroy remote-session evidence?
- What is initial access?
- What is a vulnerability?
- What is exploitation?
- What is an exploit?
- What is a zero-day vulnerability?
- Does a vulnerable system prove it was exploited?
- What is an exposed service?
- What is an unpatched system?
- What is a drive-by compromise?
- What is malicious advertising?
- What is exploitation of a public-facing application?
- What evidence may show the point of entry?
- Could an incident have several possible entry routes?
- How should uncertainty about the initial access route be reported?
- What is persistence?
- What is privilege escalation?
- What is administrator access?
- How can a new user account provide persistence?
- How can a scheduled task provide persistence?
- How can a system service provide persistence?
- What is a malicious startup item?
- How can an authentication token provide persistence?
- How can a browser extension provide persistence?
- What is an application-consent foothold?
- How can a web shell provide persistence?
- Does the presence of persistence prove it was used?
- What evidence may show when persistence was created?
- What should be preserved before persistence is removed?
- What is system discovery?
- What is network discovery?
- What is account discovery?
- What is service discovery?
- What is permission and group discovery?
- What is security-software discovery?
- What is file and directory discovery?
- Does reconnaissance prove the next stage of an attack occurred?
- What evidence may show internal reconnaissance?
- Could legitimate administration look like reconnaissance?
- What can the sequence of discovery activity tell an investigator?
- What is lateral movement?
- Does access to one system prove access to the wider network?
- What is credential reuse?
- What is pass-the-hash?
- What is remote-service execution?
- What is network-share access?
- What is account pivoting?
- What evidence may show movement between systems?
- Could legitimate administration look like lateral movement?
- How should linked events across several systems be correlated?
- Does use of an administrator account prove the administrator was responsible?
- How should the extent of lateral movement be reported?
- What is command and control?
- What is beaconing?
- Does beaconing prove an attacker was actively controlling the device?
- What is a command-and-control server?
- What is domain-based command and control?
- What is IP-based command and control?
- What is command and control over a legitimate cloud service?
- What is command and control over web traffic?
- What is command and control over DNS?
- What is a dead-drop resolver?
- What evidence may show command tasking?
- What evidence may show interactive control?
- Could legitimate administration look like command and control?
- How should command-and-control evidence be reported?
- What is data collection?
- What is data staging?
- What is exfiltration?
- Does file access prove data theft?
- Does creating an archive prove data was exfiltrated?
- What is cloud-based exfiltration?
- What is exfiltration over email or messaging?
- What is exfiltration over a remote-access session?
- What is exfiltration over removable media?
- What is exfiltration over DNS?
- What is encrypted exfiltration?
- What evidence may show that a transfer completed?
- What evidence may identify the data that left?
- Does outbound traffic volume prove data theft?
- How should suspected exfiltration be reported?
- What is ransomware?
- Does ransomware always encrypt files?
- What is double extortion?
- What is a ransom note?
- Does a ransom note prove who carried out the attack?
- What evidence may show file encryption?
- Does encryption prove data was stolen?
- What evidence may show the sequence of a ransomware incident?
- What evidence may show backup targeting?
- What evidence may show deliberate disruption?
- What should be preserved immediately in a ransomware incident?
- Should systems be rebuilt immediately after ransomware?
- Can backups be trusted after ransomware?
- What is a decryptor?
- Does successful decryption prove the incident is over?
- Should an organisation pay a ransomware demand?
- Does payment prove the payer accepted the offender’s claims?
- What evidence should be preserved from ransomware negotiations?
- What can a cryptocurrency payment prove?
- Does receiving a decryptor prove the sender caused the encryption?
- What is a ransomware leak site?
- Does removal from a leak site prove the data was deleted?
- How should ransomware attribution be approached?
- What should a final ransomware assessment distinguish?
- What is a denial-of-service attack?
- What is a distributed denial-of-service attack?
- What is a traffic-flood attack?
- What is an application-layer denial-of-service attack?
- What is reflection and amplification?
- What is a botnet-driven denial-of-service attack?
- What is resource exhaustion?
- Does a traffic spike prove an attack?
- Could a denial-of-service attack come from inside the organisation?
- What evidence may show deliberate service disruption?
- How should provider mitigation records be used?
- How should denial-of-service impact be reported?
- What is a web application attack?
- What is web scanning?
- What is directory traversal?
- What is SQL injection?
- What is cross-site scripting?
- What is command injection?
- What is file upload abuse?
- What is web-shell deployment?
- What is authentication bypass in a web application?
- What is business-logic abuse?
- How should web-attack evidence be reported?
- What is defence evasion?
- What is anti-forensics?
- What is log clearing?
- Does a missing log prove evidence was deleted?
- What is timestamp manipulation?
- What is secure deletion?
- What is data destruction?
- What is a wiper?
- What is evidence tampering?
- Could legitimate cleanup look like anti-forensics?
- What should be preserved before destructive activity is contained?
- How should destructive and anti-forensic activity be reported?
- What is insider misuse?
- Does authorised access mean the activity was legitimate?
- Does an employee account identify the employee who acted?
- What is misuse of privileged access?
- What is unauthorised data access by an insider?
- Does copying data prove malicious intent?
- What is unauthorised disclosure?
- What is insider sabotage?
- Could an insider be coerced or manipulated?
- What is account sharing?
- What is post-employment access?
- Could careless behaviour look like malicious insider activity?
- What evidence may support insider attribution?
- How should suspected insider misuse be reported?
- What is attacker infrastructure?
- What is bulletproof hosting?
- What is an initial-access broker?
- What is a proxy or relay used by an offender?
- What is a residential proxy network?
- What is a compromised website used as infrastructure?
- What is infrastructure rotation?
- What is criminal infrastructure-as-a-service?
- What evidence may identify who controlled attacker infrastructure?
- How should attacker infrastructure be reported?
- What is a supply-chain compromise?
- Does a signed software update prove the software was safe?
- What is a compromised software update?
- What is managed-service-provider compromise?
- What is abuse of a remote-management platform?
- What does “living off the land” mean?
- Does use of an administrative tool prove malicious activity?
- What is abuse of a trusted cloud service?
- What is abuse of single sign-on or identity federation?
- What is supply-chain dependency abuse?
- What evidence may show abuse of a trusted service?
- How should supply-chain and trusted-service incidents be reported?
- What is cryptomining abuse?
- What is cryptojacking?
- Does high CPU or GPU use prove cryptomining?
- What is unauthorised cloud-resource abuse?
- What is resource hijacking?
- What is automated offender activity?
- What is a bot?
- What is automated account creation?
- What is automated credential testing?
- What evidence may show automation rather than manual activity?
- How should cryptomining and automated abuse be reported?
- What does technical attribution actually mean?
- What is personal attribution?
- How should an incident timeline be built?
- How should uncertain findings be expressed?
- What should be preserved before contacting a provider?
- What should an investigator ask a provider for?
- Does a provider record prove who performed the action?
- How should preservation requests be prioritised?
- What should be recorded when containment changes the evidence?
- When should specialist support be requested?
- How should technical findings be converted into investigative actions?
- What should the final cyber-incident report achieve?