Skip to content
CIM-265 Cyber Incidents & Offender Methods

What evidence may show abuse of a trusted service?

Abuse of a trusted service is best shown by linking legitimate service records to unauthorised actions and resulting effects.

Evidential caution: that trust in the service proves trust in every action carried through it.

What this means

Useful evidence may include:

operator logins;

API calls;

job creation;

script or package deployment;

object uploads;

identity tokens;

account consent;

target lists;

provider audit logs;

endpoint execution;

later network or file activity.

which service account acted;

who controlled it;

what action was issued;

which targets received it;

whether the action was authorised;

what result followed;

whether the service itself was compromised.

The endpoint may record only a trusted agent, signed binary or cloud address.

Upstream provider and control-plane records may therefore be essential.

Where the trusted service supports automation, one authorised configuration change may produce many downstream actions. Distinguish the person who created the rule or job from the service accounts that later executed it. Endpoint repetition should not automatically be treated as repeated human decisions.

Provider-side records may use service-specific terminology such as run, task, deployment, workflow or function. Preserve native identifiers and map them to endpoint events rather than translating everything into generic commands too early.

This preserves the original evidential meaning and allows later specialist review.

This preserves the original evidential meaning and allows later specialist review of the service records. The operational takeaway is:

Correlate service-side operator and action records with target-side effects, and distinguish trusted delivery from authorised purpose and personal control.

================================================================================

What to check or do next

  • Investigators should establish:

Evidential limits

Do not assume the provider, subscriber or account owner personally performed the action.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.