Logs, Records & Provider Evidence¶
155 investigator questions.
Use the list below or search the complete library.
- A log, event or alert may be relevant to my investigation — where do I start?
- What is a log?
- What is an event?
- What is the difference between a log entry and an event?
- What is an alert?
- What is the difference between an alert and the underlying evidence?
- What can a single log entry actually prove?
- What can a log entry not prove?
- Does a log entry identify a person?
- Does a username in a log identify the user?
- Does a device name in a log identify the physical device?
- Does an IP address in a log identify the user?
- What should I preserve when I first receive log evidence?
- What questions should I ask the person who supplied the logs?
- What is a system log?
- What is an application log?
- What is an authentication log?
- What is an audit log?
- What is a security log?
- What is a network log?
- What is a firewall log?
- What is a proxy log?
- What is a DNS log?
- What is a VPN log?
- What is a web-server access log?
- What is an email-security log?
- What is a cloud audit log?
- What is an endpoint-security log?
- What is an identity-provider log?
- What is a database audit log?
- What is a mobile-device-management log?
- What is an administrator activity log?
- What is a physical-access or door-entry log?
- What is a transaction log?
- What is a service or process log?
- What is a raw log?
- Why should investigators preserve the original log source?
- What is a log export?
- Could an export omit fields or records?
- What is normalised log data?
- What is enriched log data?
- What is the difference between a source event and a dashboard entry?
- Could a SIEM change how an event is displayed?
- What is log parsing?
- Could parsing errors change the meaning of a field?
- What is a data connector or log collector?
- Could a collector delay or lose events?
- What is log ingestion?
- What is an ingestion timestamp?
- What is the difference between event time and ingestion time?
- Why should field definitions be requested?
- What is a vendor-specific event code?
- What is an event ID?
- What is a correlation ID?
- What is a session ID in a log?
- What is a request ID or trace ID?
- What does a timestamp in a log actually prove?
- Which clock created the timestamp?
- Why does the time zone matter?
- What is UTC?
- What is the difference between UTC and local time?
- Could daylight-saving changes affect a timeline?
- What is clock drift?
- Could a device clock be wrong?
- Could a server and client record different times for the same event?
- What is timestamp precision?
- Does a timestamp show when the user acted or when the system recorded the event?
- Could buffering or delayed upload change the recorded time?
- What is an ingestion delay?
- Why might several logs show different times for the same activity?
- How should investigators convert times safely?
- How should time uncertainty be reported?
- Does a recorded event prove that a person caused it?
- What is a system-generated event?
- What is a user-generated event?
- What is a service-account event?
- What is a scheduled-task event?
- Could a script or application generate the event?
- Could background synchronisation generate log activity?
- Could security software generate the event?
- Could an administrator generate activity on behalf of another user?
- Could an API generate account activity?
- What is a machine account?
- What is a service principal?
- Could remote access make activity appear local?
- Could a compromised session generate apparently legitimate events?
- How should automated activity be distinguished from human action?
- What does a successful login event prove?
- What does a failed login event prove?
- Does a successful login prove that the password was known?
- Could a session continue without a new login event?
- What is a token-based authentication event?
- What is a session-refresh event?
- What is a multi-factor authentication event?
- Does an MFA approval prove that the account holder approved it?
- What is a password-reset event?
- What is an account-lockout event?
- What is an account-disable event?
- What is a new-device or unfamiliar-login event?
- Could an attacker produce normal-looking authentication events?
- How should authentication events be attributed to a person?
- What is a SIEM?
- What does a SIEM alert prove?
- What is a detection rule?
- What is a correlation rule?
- What is a threshold alert?
- What is an anomaly alert?
- What is a risk score?
- Does a high-severity alert prove malicious activity?
- What is a false positive?
- What is a false negative?
- Could an alert be generated from incomplete data?
- Could a rule change after the event?
- Why should the rule version be preserved?
- What should be requested alongside an alert?
- Why should the underlying source events be examined?
- What does an analyst closure or disposition prove?
- Could several alerts relate to the same underlying event?
- Could one incident generate alerts across several systems?
- Does the absence of a log entry prove that an event did not happen?
- Why might an expected log entry be missing?
- Could logging have been disabled?
- Could the relevant event type have been filtered out?
- Could retention have expired?
- Could storage limits overwrite older logs?
- Could a system fail before writing the event?
- Could an attacker delete or alter logs?
- What is log tampering?
- What evidence may indicate log deletion?
- Could a gap be caused by maintenance or outage?
- Could different account tiers retain different records?
- What should investigators ask about retention?
- When should a preservation request be considered?
- What is event correlation?
- Does matching time prove that two records relate to the same event?
- How can account, device, session and network events be linked?
- How should logs from several systems be compared?
- What is a defensible digital timeline?
- What should be recorded about each timeline entry?
- How should contradictory logs be handled?
- Could one system record the start while another records completion?
- Could retries create several records for one action?
- Could one event create several downstream events?
- What is causation versus correlation in a timeline?
- How should gaps in a timeline be shown?
- How should uncertain event order be reported?
- When should specialist timeline analysis be sought?
- How should a log entry be described in an investigative report?
- How should an alert be described in a report?
- How should attribution from logs be worded?
- How should timestamp uncertainty be reported?
- How should missing records be reported?
- What are the most common mistakes when interpreting logs?
- When should a log line of enquiry stop?
- What is the overall investigator checklist for logs, events, alerts and timelines?