Which systems, accounts, devices and providers may hold evidence?¶
Think of the incident as being observed from several different places.
The endpoint sees processes and files. The identity service sees authentication. The network sees connections. Applications see account activity. Security tools see telemetry. External providers may see infrastructure, communications or payments.
Your job is to work out which observer can answer which part of the incident.
Build an evidence map around the event¶
A useful starting map might be:
| Evidence source | What it may show |
|---|---|
| Endpoint | Processes, files, local users, connections |
| Identity service | Login, MFA, sessions, tokens, revocation |
| Application / cloud service | Account activity, files, messages, admin changes |
| Network / firewall / proxy | Source, destination, DNS, traffic path |
| Security platform | Alerts, detections, endpoint/network telemetry |
| Email system | Delivery, mailbox and account events |
| External provider | Hosting, domain, communications or payment records |
| Response team | Decisions, containment and recovery chronology |
No single source needs to contain the whole story.
Use shared identifiers to join the views¶
Useful pivots include:
- account ID;
- username;
- session ID;
- device or host name;
- IP address;
- message ID;
- file hash;
- tenant ID;
- correlation/request ID;
- exact timestamps.
S-4812Authentication and account context.The repeated values are what let you test whether the records describe the same incident sequence.
Record missing observers too¶
An evidence map should also show gaps.
For example:
- endpoint sensor not installed;
- firewall retention expired;
- cloud audit disabled;
- device unavailable;
- provider records not yet preserved.
Those gaps matter when somebody later asks why a record is missing.
Prioritise the sources that answer the question¶
Do not collect every possible log simply because it exists.
If the question is who accessed an account, identity/session/device records may be more useful than terabytes of network telemetry.
If the question is whether files were copied, endpoint and file/audit records may be central.
If the question is attribution, provider, device and real-world evidence may matter most.
The practical point is: map the systems that could see each stage of the incident, then use stable identifiers and time to join the most useful records into one reconstruction.