Skip to content
CIM-103 Cyber Incidents & Offender Methods

What evidence may show the point of entry?

The point of entry should be established from the earliest supported evidence of unauthorised access.

Avoid the dangerous assumption

The dangerous assumption is that the first alert or obvious harmful action identifies how the offender entered.

It may not.

Useful evidence may include:

  • the first suspicious authentication
  • the first malicious process
  • the first exploit request
  • the first new session
  • the first unauthorised account change
  • the first remote-access connection
  • the first malicious file delivery
  • the first application-consent event.

Investigators should compare several timelines.

Event time, alert time, discovery time and response time may differ.

Look for evidence that links one stage to the next:

  • a phishing message followed by a sign-in
  • an exploit request followed by process execution
  • a new session followed by persistence
  • a malicious download followed by network contact.

Do not force a single point of entry where the evidence supports only a window or several possible routes.

A system may already have been compromised before logging began.

Records may have expired or been deleted.

The earliest surviving event may not be the first actual event.

Preserve the reasoning behind the proposed entry route and identify what evidence would challenge it.

Check whether the earliest event could reflect testing, reconnaissance or failed access rather than a foothold. The point of entry should mark supported unauthorised access, not merely the first suspicious contact.

That distinction prevents the timeline beginning too early.

Use that distinction consistently.

Operational takeaway

Define the earliest supported foothold from linked events and report any uncertainty, gaps or alternative entry routes explicitly.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.