Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

Does reconnaissance prove the next stage of an attack occurred?

No. Reconnaissance tells you what somebody learned about the environment. You still need to look for the records showing whether they then did anything with that information.

That distinction is useful because it gives you a very practical way to investigate what happened next.

Follow the thing that was discovered

Suppose a Windows session finds an account called svc-backup.

That discovery immediately gives you something worth following.

Ten minutes later, an authentication log shows an attempt to use svc-backup against an internal server. The server then records a successful sign-in and a process starting.

That is the basic method: take what was discovered and look for it again later.

Different discoveries give you different things to chase

If discovery reveals… Look next for…
An account Authentication attempts or later use of that account
An internal host Connections to that host
A service Authentication, exploitation or service activity
A file or share Access, copying, staging or archiving
A security product Changes to its configuration or operation

The neighbouring explanations go into the individual discovery types: network discovery, service discovery and file and directory discovery.

Build the timeline as far as the evidence takes you

You do not need to force every incident into a complete attack chain.

If svc-backup appears in discovery output and nothing else ever mentions it, that may genuinely be where the evidence stops.

If an authentication attempt appears later, you have another stage.

If that becomes a successful sign-in followed by activity on the target, the story develops again.

The important thing is not to jump over the missing steps. Record what you actually have:

  1. what was discovered;
  2. whether the same target appears later;
  3. what action was attempted;
  4. whether it worked; and
  5. what happened after that.

Sometimes logging will be incomplete or retention will have expired. That is frustrating, but the discovery event is still useful because it tells you which accounts, hosts, services or files were known to the session and therefore where it makes sense to look.

What evidence may show internal reconnaissance? looks at the different records you can combine, while the sequence of discovery activity shows how the order itself can be useful.

The practical point is: reconnaissance gives you targets to follow. It does not, by itself, tell you how far the incident went.

Reference: CIM-127Cyber Incidents & Offender Methods