Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

Which systems, accounts, devices and providers may hold evidence?

Think of the incident as being observed from several different places.

The endpoint sees processes and files. The identity service sees authentication. The network sees connections. Applications see account activity. Security tools see telemetry. External providers may see infrastructure, communications or payments.

Your job is to work out which observer can answer which part of the incident.

Build an evidence map around the event

A useful starting map might be:

Evidence source What it may show
Endpoint Processes, files, local users, connections
Identity service Login, MFA, sessions, tokens, revocation
Application / cloud service Account activity, files, messages, admin changes
Network / firewall / proxy Source, destination, DNS, traffic path
Security platform Alerts, detections, endpoint/network telemetry
Email system Delivery, mailbox and account events
External provider Hosting, domain, communications or payment records
Response team Decisions, containment and recovery chronology

No single source needs to contain the whole story.

Use shared identifiers to join the views

Useful pivots include:

  • account ID;
  • username;
  • session ID;
  • device or host name;
  • IP address;
  • message ID;
  • file hash;
  • tenant ID;
  • correlation/request ID;
  • exact timestamps.
IdentitySession S-4812Authentication and account context.
EndpointHost FILE-03Process and file activity.
Network203.0.113.42 → FILE-03Connection path and timing.
ApplicationEvent tied to same account/timeService-specific activity.

The repeated values are what let you test whether the records describe the same incident sequence.

Record missing observers too

An evidence map should also show gaps.

For example:

  • endpoint sensor not installed;
  • firewall retention expired;
  • cloud audit disabled;
  • device unavailable;
  • provider records not yet preserved.

Those gaps matter when somebody later asks why a record is missing.

Prioritise the sources that answer the question

Do not collect every possible log simply because it exists.

If the question is who accessed an account, identity/session/device records may be more useful than terabytes of network telemetry.

If the question is whether files were copied, endpoint and file/audit records may be central.

If the question is attribution, provider, device and real-world evidence may matter most.

The practical point is: map the systems that could see each stage of the incident, then use stable identifiers and time to join the most useful records into one reconstruction.

Reference: CIM-009Cyber Incidents & Offender Methods