Which systems, accounts, devices and providers may hold evidence?¶
Cyber incidents rarely leave evidence in only one place.
Evidential caution: that the affected device or the organisation’s central server will contain the complete record.
What this means¶
A single event may create traces across several layers.
The endpoint may record processes, files, user activity and network connections.
The identity platform may record authentication, device, session and risk information.
The email system may record message delivery, links and mailbox actions.
Network systems may record connections, DNS requests, proxy use and traffic volume.
Cloud applications may record administrative actions, file access, sharing and API activity.
Security providers may hold alerts, telemetry and analyst notes.
Internet, hosting or communications providers may hold subscriber, connection or account records.
The offender’s infrastructure may create further records with domain registrars, cloud platforms, hosting companies or payment providers.
Build an evidence map around the investigative question.
For each relevant action, ask:
which system performed it;
which account authorised it;
which device initiated it;
which service processed it;
which provider may have recorded it;
which identifier links the records together.
Useful linking identifiers may include account names, email addresses, device IDs, hostnames, IP addresses, session IDs, message IDs, file hashes, cloud tenant IDs and correlation IDs. None should be assumed to identify a person without corroboration.
The goal is not to collect every possible log. It is to identify the records most capable of answering the specific investigative question.
================================================================================
Evidential limits¶
Also identify logging gaps. A system may not have recorded the activity, logging may have been disabled or retention may have expired.
Operational takeaway
Map each suspected action across the systems, accounts, devices and providers that may have recorded it, then prioritise the records that answer the investigation.