Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

How should destructive and anti-forensic activity be reported?

Report missing evidence, observed alteration, technical success, intent, responder change and attribution as separate propositions. The term anti-forensics must not turn an evidential gap into certainty.

Use action-specific language

Distinguish a log never generated from a log cleared, a present wiping tool from successful storage overwrite, and an inconsistent timestamp from deliberate manipulation. State the account, process, command, timing and effect where known.

Identify whether each conclusion rests on direct events, comparison with earlier state or inference from absence. Explain expected evidence and alternative causes.

Record response changes transparently

Containment may terminate sessions, alter files and overwrite logs. Include those responder effects in the timeline so they are not attributed to the offender.

State whether intent is directly evidenced, strongly supported or uncertain. Technical account activity should not become personal attribution without separate controller evidence.

Key takeaway

Report absence, alteration, destruction, intent and responsibility independently, including all response actions that changed the evidence.

Reference: CIM-230Cyber Incidents & Offender Methods