What is data collection?¶
The practical answer¶
Data collection is the process of identifying, accessing and gathering information that may be useful to an offender.
The key evidential caution¶
The dangerous assumption is that discovering or opening data proves it was stolen.
It does not.
Collection may involve:
Key points¶
- searching for files
- opening documents
- copying data
- exporting records
- querying databases
- capturing screenshots
- collecting browser information
- gathering email
- accessing cloud storage
- reading configuration or credentials
Investigators should separate:
- discovery
- access
- selection
- copying
- staging
- transfer
- use
Each stage may create different evidence.
A directory listing may show what files existed.
A file-open event may show access.
A copy or export may show collection.
A network transfer may support exfiltration.
Evidential limits¶
Do not assume that every accessed file was deliberately selected. Applications, indexing, backup and security tools may create similar records.
The account used may also be shared, compromised or automated.
Relevant evidence¶
Relevant evidence may include file-access logs, application audit records, database queries, cloud events, process activity, archive creation and network traffic.
Collection may occur gradually or in one large operation.
It may also be limited to information viewed on screen without a separate copied file.
Where collection occurs through an application or database, preserve the query, export parameters and object identifiers. Those records may show the selected scope more reliably than later filenames. Collection can also happen through screenshots, clipboard capture or printing, which may leave different evidence from conventional file copying.
Record that distinction explicitly.
Operational takeaway¶
Separate discovery, access, copying, staging and transfer, and prove each stage before concluding that data was collected or stolen.