What could a cyber incident contribute to my investigation?¶
Potentially a great deal.
Incident records can help establish how access happened, what systems were touched, what accounts were used, what activity followed and what impact occurred.
Even where the person responsible is not yet known, the technical sequence can give you strong lines of enquiry.
Incident evidence can answer different questions¶
For example:
| Investigative question | Incident evidence may show |
|---|---|
| Was an account accessed? | Authentication and session records |
| Did somebody reach another system? | Network, remote-service and target-host events |
| Was data opened or copied? | File, application and process records |
| Was activity automated? | Process, script, scheduling and timing patterns |
| Was a control disabled? | Configuration, service and security-tool events |
| Was the business disrupted? | Availability, file-change and response records |
That can move an enquiry forward even before attribution is complete.
A sequence is often more useful than one event¶
Imagine this progression:
That sequence tells you much more than any single alert.
It may show how the incident developed and which records to pursue next.
Technical evidence can also rule things out¶
Incident evidence is useful when it supports an alternative explanation too.
A supposed “attack” may turn out to be:
- authorised administration;
- a blocked attempt;
- a failed transfer;
- scheduled automation;
- a misconfigured service;
- or legitimate user activity.
A strong investigation is improved by proving that the technical explanation fits — whichever way it points.
Connect the incident to the wider case¶
System records may establish an account, session, device or connection.
Wider evidence may establish:
- who controlled the device;
- who had access to the account;
- who benefited;
- who communicated about the activity;
- what the person knew; and
- what happened in the real world.
The practical point is: cyber incident evidence can establish a detailed technical story and give you precise things to follow. Use that story as part of the case rather than expecting one log or alert to identify the person responsible.