Does use of an administrator account prove the administrator was responsible?¶
The practical answer¶
No. Use of an administrator account does not automatically prove that the named administrator was responsible.
The key evidential caution¶
The dangerous assumption is that account attribution equals personal attribution.
The account may have been:
Key points¶
- shared
- compromised
- used by an automated service
- accessed through remote management
- used from a compromised device
- delegated
- left active in an existing session
What investigators should establish¶
Investigators should establish:
Key points¶
- who knew or controlled the credential
- which device and session used it
- what authentication method applied
- whether multi-factor authentication was involved
- whether the administrator was working at the time
- whether the action matched their role and normal pattern
- what other corroboration exists
The administrator’s explanation should be tested against the records.
Evidential limits¶
Do not treat denial as proof of compromise or account use as proof of guilt.
Likewise, an administrator may be responsible even where the activity passed through automated tools, if they configured or directed it.
Relevant evidence¶
Relevant evidence may include source devices, session identifiers, remote-access records, change tickets, communications, command history and witness accounts.
The timing of account use should also be compared with the administrator’s device, physical access, communications and approved work. No single factor is decisive, but several independent records may materially strengthen or weaken attribution.
Conflicts should be recorded rather than resolved by assumption.
The conclusion should reflect the combined evidential picture.
Where the account was used from several devices or locations, preserve the full session history. One legitimate session does not explain every action recorded against the account.
Operational takeaway¶
Treat administrator-account use as technical attribution to an identity, and require device, session, behavioural and contextual evidence before attributing the action to the person.