Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

Could an incident have several possible entry routes?

Yes. Several routes may remain plausible, and more than one may actually have been used. An offender could hold stolen credentials while exploiting a public service, or separate actors could enter the same environment independently.

Investigation and containment do not need an artificially singular explanation.

Test each route as a hypothesis

For every candidate route, define the access it would provide, affected systems, expected records and timing. Compare those expectations with surviving authentication, application, endpoint and network evidence, including facts that contradict the route.

Do not treat possible routes as equally supported. One may be confirmed by linked events, another consistent with gaps, and a third merely technically conceivable. Use confidence language that preserves those differences.

Keep later findings independent

Uncertainty about entry does not erase strong evidence of later persistence, data access or impact. Report those findings independently while explaining which entry routes could have enabled them.

Multiple routes also affect response. Resetting one account or patching one service may leave another foothold active; continued activity can expose that incomplete model. Preserve broadly enough before narrowing the assessment and test containment against every supported route.

Key takeaway

Assess each possible route against its expected evidence and consequences; do not force one entry point where several routes remain differently supported.

Reference: CIM-104Cyber Incidents & Offender Methods