Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What evidence may show the point of entry?

The point of entry is supported by the earliest linked evidence that an unauthorised foothold was obtained - not necessarily the first alert, harmful action or suspicious contact.

Build linked timelines

Compare authentication, message delivery, exploit requests, process execution, remote sessions, account changes and application-consent events. Look for transitions: a phishing message followed by a new sign-in, or an exploit request followed by a server process and persistence.

Keep event time, alert time, discovery time and response time separate. A delayed alert can make later activity appear earlier in a discovery timeline than the access event that caused it.

The first scan, failed login or reconnaissance request is not a foothold. Mark entry where the evidence first supports actual unauthorised access, execution or control.

State what may predate the evidence

Logging may have begun after compromise, and older records may have expired or been deleted. The earliest surviving event therefore sets an evidential boundary, not necessarily the true start.

Where evidence supports only a window or several routes, preserve that uncertainty. Record why the proposed route fits, which gaps remain and what evidence could challenge it. A defensible window is more useful than a precise but assumed timestamp.

Key takeaway

Establish entry from the earliest linked foothold, distinguish it from suspicious contact and discovery, and report any earlier unobserved period explicitly.

Reference: CIM-103Cyber Incidents & Offender Methods