Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What evidence may show deliberate service disruption?

Deliberate disruption requires a supported link between an intentional activity and service impact. Technical effect alone cannot establish intent.

Prove action and consequence

Commands, abusive requests, service stops, configuration changes, exhaustion patterns, malware tasks and repeated attacks may connect a source to outage or degradation. Establish mechanism, affected resource, timing, system response and whether the likely result was disruption.

Automation can execute an intentional plan without a human sending each request. Conversely, a reckless or faulty process can cause serious harm without an evidenced purpose to disrupt.

Explain the intent inference

Prior threats, target selection, persistence after blocking, method changes and requests designed to maximise cost can support intent. A threat before an outage has different weight from a later claim seeking credit.

Preserve failed attempts and the progression after mitigation. Adaptation may show the actor observed the effect and changed method, but state that inference explicitly rather than hiding it inside an attack label.

Key takeaway

Link the disruptive action to its resource effect and support intent through commands, threats, repetition, targeting or adaptation - not impact alone.

Reference: CIM-205Cyber Incidents & Offender Methods