Where information is held.
WHAT SYSTEMS RETAIN
Files, including deleted ones in some circumstances Timestamps of creation, modification and access Records of what programs ran Authentication records Network connection records Browser and application history Communications
WHY DELETED FILES MAY REMAIN
Deletion frequently removes the reference rather than the content, until the space is reused.
WHAT THAT MEANS
Continued use of a system reduces what can be recovered.
WHAT TIMESTAMPS PROVIDE
A sequence of events.
WHAT TO BE CAREFUL WITH
Timestamps can be altered, and interpreting them requires care.
WHY
Different systems record different things and time zones differ.
WHAT TO ESTABLISH
What time source systems use, and whether they agree.
WHY
Correlating events across systems requires consistent time.
WHAT NETWORK RECORDS PROVIDE
What connected to what, and when.
WHERE THEY EXIST
Firewalls Routers and switches Proxies Hosting and cloud providers
WHY THEY MATTER
They show activity that a compromised system may not record.
WHAT CLOUD AND SERVICE PROVIDERS HOLD
Authentication records Administrative actions Data access, in some services Configuration changes
WHAT TO ESTABLISH
What each provider retains and for how long.
WHY IN ADVANCE
Discovering they retain nothing after an incident is too late.
WHAT TO ENABLE NOW
Logging that will be needed later.
WHAT TO CONSIDER
Retention long enough for delayed discovery.