Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What evidence may identify the data that left?

Identify transferred data by linking source records to the content or metadata accepted at the destination. Traffic volume alone cannot name the files involved.

Compare hashes, sizes, filenames, timestamps, folder structures, object IDs, upload manifests, export parameters and recovered recipient copies. Archive contents, mailbox or database exports, cloud objects and removable-media files can provide direct scope evidence.

Compression, encryption, renaming, splitting and combination may prevent one-to-one comparison. A matching name is weak where content or stable metadata differs, and every file in a staging folder was not necessarily transferred.

Report supported scope

Where exact items cannot be proved, identify the strongest supported category or boundary: a mailbox, database table, project folder or minimum set of confirmed documents.

One recovered document proves at least that item, not the entire suspected archive. Distinguish confirmed content, material likely included through corroboration and data merely present in the same source location. Avoid invented precision or unsupported maximum claims.

Key takeaway

Link source and destination through content or stable metadata, and report a defensible minimum, category or uncertainty where exact files cannot be established.

Reference: CIM-169Cyber Incidents & Offender Methods