Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What could a cyber incident contribute to my investigation?

Potentially a great deal.

Incident records can help establish how access happened, what systems were touched, what accounts were used, what activity followed and what impact occurred.

Even where the person responsible is not yet known, the technical sequence can give you strong lines of enquiry.

Incident evidence can answer different questions

For example:

Investigative question Incident evidence may show
Was an account accessed? Authentication and session records
Did somebody reach another system? Network, remote-service and target-host events
Was data opened or copied? File, application and process records
Was activity automated? Process, script, scheduling and timing patterns
Was a control disabled? Configuration, service and security-tool events
Was the business disrupted? Availability, file-change and response records

That can move an enquiry forward even before attribution is complete.

A sequence is often more useful than one event

Imagine this progression:

10:14Unusual account authentication succeeds.
10:18The same session queries internal systems.
10:23A newly discovered server records remote access.
10:31Files on that server are copied into an archive.

That sequence tells you much more than any single alert.

It may show how the incident developed and which records to pursue next.

Technical evidence can also rule things out

Incident evidence is useful when it supports an alternative explanation too.

A supposed “attack” may turn out to be:

  • authorised administration;
  • a blocked attempt;
  • a failed transfer;
  • scheduled automation;
  • a misconfigured service;
  • or legitimate user activity.

A strong investigation is improved by proving that the technical explanation fits — whichever way it points.

Connect the incident to the wider case

System records may establish an account, session, device or connection.

Wider evidence may establish:

  • who controlled the device;
  • who had access to the account;
  • who benefited;
  • who communicated about the activity;
  • what the person knew; and
  • what happened in the real world.
Technical sequenceWhat did the systems record?Access, movement, files, services and impact.
AttributionWho controlled the account/session/device?Provider, device and real-world evidence.
Case conclusionWhat does the combined evidence support?Keep technical facts and personal responsibility separate until the evidence joins them.

The practical point is: cyber incident evidence can establish a detailed technical story and give you precise things to follow. Use that story as part of the case rather than expecting one log or alert to identify the person responsible.

Reference: CIM-004Cyber Incidents & Offender Methods