Skip to content
CIM-003 Cyber Incidents & Offender Methods

Is this a source record, security alert, incident ticket, intelligence report or somebody’s summary?

Cyber material often arrives with authority because it came from a technical team. That does not tell you what kind of material it is.

Evidential caution: that every document in an incident file directly records what happened.

What this means

A source record is data created by a system or service as activity occurs. Examples include authentication logs, endpoint events, firewall records or cloud audit entries.

A security alert is a notification that defined conditions were met. It may combine several records and apply a product rule, model or risk threshold.

An incident ticket is a working record used to coordinate response. It may contain observations, decisions, copied alerts, hypotheses and later updates.

An intelligence report usually draws together information from several sources. It may assess likely infrastructure, methods or threat actors, but it is not normally the original evidence of activity on the affected system.

A summary is somebody’s explanation of what they believe occurred. It may be useful and accurate, but investigators should identify the records and reasoning beneath it.

Retain both the original records and the interpretations. The difference between them should remain visible in any investigative report.

================================================================================

What to check or do next

  • Do not dismiss derived material. Alerts, tickets and reports may help you understand the sequence and locate evidence. The issue is whether they are being used for the right purpose.

Evidential limits

Ask the provider to label each item clearly. For every conclusion, ask: what underlying record supports this, who interpreted it and what alternative explanations were considered?

A ticket may prove that an organisation received and acted upon a report. It may not prove that every technical statement in the ticket is correct. An intelligence match may identify similarities with known activity. It may not identify the offender in your case.

Operational takeaway

Separate direct system records from alerts, intelligence and human interpretation, and make clear which layer supports each conclusion.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.