Knowledgebase

Understanding What Evidence Exists Print

  • 0

Where information is held.

WHAT SYSTEMS RETAIN

Files, including deleted ones in some circumstances Timestamps of creation, modification and access Records of what programs ran Authentication records Network connection records Browser and application history Communications

WHY DELETED FILES MAY REMAIN

Deletion frequently removes the reference rather than the content, until the space is reused.

WHAT THAT MEANS

Continued use of a system reduces what can be recovered.

WHAT TIMESTAMPS PROVIDE

A sequence of events.

WHAT TO BE CAREFUL WITH

Timestamps can be altered, and interpreting them requires care.

WHY

Different systems record different things and time zones differ.

WHAT TO ESTABLISH

What time source systems use, and whether they agree.

WHY

Correlating events across systems requires consistent time.

WHAT NETWORK RECORDS PROVIDE

What connected to what, and when.

WHERE THEY EXIST

Firewalls Routers and switches Proxies Hosting and cloud providers

WHY THEY MATTER

They show activity that a compromised system may not record.

WHAT CLOUD AND SERVICE PROVIDERS HOLD

Authentication records Administrative actions Data access, in some services Configuration changes

WHAT TO ESTABLISH

What each provider retains and for how long.

WHY IN ADVANCE

Discovering they retain nothing after an incident is too late.

WHAT TO ENABLE NOW

Logging that will be needed later.

WHAT TO CONSIDER

Retention long enough for delayed discovery.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot