Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What should an investigator ask a provider for?

Ask for the native records needed to answer a defined question about a specific account, object, session or event. A request for “all logs” is unlikely to be complete, consistently interpreted or easy to assess.

The precise legal route depends on the case and jurisdiction; the technical task is to define the records and identifiers accurately.

Work backwards from the question

Possible record categories include:

  • account creation, recovery and linked identifiers;
  • authentication, session, device and multi-factor events;
  • administrator, API and application-consent activity;
  • message, file, object or resource creation and access;
  • payment, subscription and billing records;
  • deletion, retention, alert and enforcement events; and
  • native timestamps and source identifiers.

Specify the identifier, time range and time zone, relevant event type, and whether historical or deleted records matter. Distinguish account-level history from the event under investigation: registration and login records may not show who accessed a particular object or sent a particular message.

Use the provider's definitions

“Login,” “session,” “access,” “device” and “API call” may refer to separate records or derived fields. Where possible, request field definitions, generation details and retention limits with the native data.

If a requested field is unavailable, ask whether another record addresses the same question. Token, audit, security and device records can overlap without being equivalent. Record what the provider says it cannot supply rather than assuming the underlying event never existed.

Key takeaway

Frame provider enquiries around a precise identifier and evidential question, and seek native records with field definitions, time basis and retention limits.

Reference: CIM-283Cyber Incidents & Offender Methods