Deutsch

Digital Forensics

Network Forensics

An attacker can delete traces on a machine. The traffic they generated while doing so cannot be taken back. That is why the network is often the most dependable source once the endpoints have already been tidied up.

A dense mesh of faint connection lines in the dark. One single path is brightly highlighted throughout and can be followed from one end to the other.

The basis

Which sources we work from

In most cases full packet captures are not available. That is not a blocker — from flow and DNS data the sequence of events can as a rule be reconstructed dependably.

  1. 01

    Full packet captures where they exist — the most complete but rarest source

  2. 02

    Flow data such as NetFlow or IPFIX

    who talked to whom, when and for how long

  3. 03

    DNS logs

    often the first pointer to command-and-control servers

  4. 04

    Proxy and firewall logs

    destinations, data volumes, blocked attempts

  5. 05

    VPN and remote-access logs

    sign-ins, times, source addresses

The result

What comes out of it

  1. 01

    Timeline of the attack from first contact to last access

  2. 02

    Identification of the command infrastructure and how it was reached

  3. 03

    Proof or exclusion of data exfiltration, with an order of magnitude

  4. 04

    Affected systems, including those with no conspicuous endpoint traces

  5. 05

    Detection rules for a repeat case

01

The time pressure

Keeping the reporting deadline in view

Whether personal data left the organization decides the reporting obligation under the GDPR — and that leaves 72 hours. Network forensics is often the only way to answer that question dependably instead of reporting as a precaution. So we order the analysis around that deadline.

02

Beforehand

Preparation pays off

How good a later investigation turns out is decided before the incident: is flow data collected at all? How long is it retained? Are the clocks in sync? We check that as part of the ISMS build-up and set up collection so that it holds when it matters. Ongoing analysis then happens in Strider.

FAQ

Frequently asked questions

We do not capture network traffic. Is an investigation still possible?

As a rule, yes. Full captures are almost never available, so an investigation relies mostly on flow, DNS, proxy and firewall logs anyway. From those the sequence of events can usually be reconstructed dependably. What is missing is the content of the connections — not the connections themselves.

Can you say for certain whether data was exfiltrated?

Often yes, and that is usually the decisive question. Flow data shows how much went in which direction; DNS and proxy show where to. What normally stays open without a full capture is the exact content. We write into the report what is evidenced and what is not — presenting a presumption as a finding does not help you with the notification.

How long do logs need to be retained for this to work?

In practice, weeks to months pass between initial access and discovery. Logs overwritten after two weeks no longer cover the beginning of the incident. We recommend retention well beyond that — the exact period we settle against your data protection requirements.

Why do synchronised clocks matter so much?

A timeline is built by laying events from different sources side by side. If clocks differ by minutes, the order shifts — and with it the statement about what was cause and what was effect. In court such a timeline is attackable. Time synchronisation costs nothing and decides retrospectively whether the evidence holds.

Does the investigation disrupt ongoing operations?

No. We work on copies of the logs, not on the systems themselves. Where a capture has to be set up, it is done through a mirror port or a passive tap — the traffic continues unchanged.

Digital Forensics

More in this area

Malware Analysis

We take malware apart in an isolated environment and deliver concrete detection rules for your systems rather than a la…

View

Cloud Forensics

There is no disk to image in the cloud. We secure logs, configuration states and identity data before the provider rete…

View

Mobile Forensics

Company phones often hold more business secrets than any computer. We secure and examine them to an evidentiary standar…

View

Behavioural Forensics

Tools change, habits persist. We analyse how an attacker operates and derive where they will start next time.

View

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.