Establishing what an attacker did.
WHAT TO ESTABLISH
How they got in What they reached What they took or changed Whether they still have access When it began
WHY THE LAST QUESTION MATTERS MOST
The starting point determines the scope of everything.
WHAT TO AVOID ASSUMING
That the incident began when you noticed it.
WHY
Compromises are typically present long before discovery.
WHAT TO DO
Work backwards from the earliest evidence.
WHAT TO EXAMINE
Authentication records for unusual access Accounts created or modified Software installed Scheduled tasks created Network connections to unfamiliar destinations Files added or changed Configuration changes
WHY SCHEDULED TASKS AND ACCOUNTS
They are how access is retained after the original route is closed.
WHAT TO ESTABLISH BEFORE CONCLUDING
That every route back in has been found.
WHY
Removing the obvious one and leaving another means the compromise continues.
WHAT TO ASSESS ABOUT DATA
What was accessible to the compromised account Whether large transfers occurred Whether anything was staged for extraction
WHY STAGED DATA
Collected files awaiting transfer indicate intent and scope.
WHAT TO ESTABLISH ABOUT OTHER SYSTEMS
Whether the compromise spread.
HOW
Look for the same indicators elsewhere.
WHAT TO ASSUME ABOUT CREDENTIALS
That anything accessible from the compromised system is compromised.
WHAT TO DO
Change them.
WHAT TO RECORD
The timeline, with evidence for each point.