The outcome of a digital forensics investigation is decided months before the incident, by what you were recording and how long you kept it.
The short answer
Digital forensics is the disciplined collection, preservation and analysis of evidence from systems, in a way that holds up when someone challenges it. In a breach it answers how the attacker got in, what they reached, what left the building and whether they are still there. Everything it can tell you depends on data that existed before anyone knew there was a problem.
That constraint is why digital forensics is a preparation exercise far more than a response one.
On this page
The four questions digital forensics answers
| Question | Why it matters |
|---|---|
| How did they get in | Until the entry route is known, closing it is guesswork and reinfection is likely |
| What did they reach | Determines the scope of the breach and, in most jurisdictions, whether notification is required at all |
| What left | Regulators and customers ask what data was taken. Not knowing is usually treated as the worst answer |
| Are they still here | The question that decides whether you can safely resume operations, and the one most often answered too early |
The four digital forensics phases
Preservation is the phase that goes wrong. Investigating a live system changes it, so the working copy must be taken first and verified against the original by hash. Everything after that runs on the copy.
Retention decides the outcome
Every digital forensics engagement runs into the same wall. An investigator can only reconstruct what was written down. Default retention on most sources is shorter than the time attackers typically remain undetected, which is why so many investigations end without an answer.
| Evidence source | What it proves, and the catch |
|---|---|
| Identity and sign-in logs | The most valuable source in a cloud breach. Free tiers of most providers keep them for a matter of weeks |
| Cloud audit trails | Records API calls and configuration changes, but only if the trail was switched on before the incident and written somewhere the attacker could not reach |
| Endpoint telemetry | Process execution and network connections. Endpoint detection keeps this. Plain antivirus does not |
| Email logs | Shows what was accessed, forwarded or exported. Retention varies sharply by licence tier |
| Network flow records | Reveals volume leaving and where it went. Rarely retained by default anywhere |
| Memory | Running processes, live connections, keys and unencrypted data. Gone the moment the machine is powered off |
Extend retention before you need it, not after
Intrusions are frequently discovered months after they begin, and a ninety-day log window investigated on day one hundred and twenty produces a report that says the entry point could not be determined. That sentence in a customer notification is worse than the breach. Longer retention on identity, cloud audit and endpoint telemetry is the cheapest digital forensics investment available, and it has to be bought before anything happens because logs cannot be created retrospectively.
What destroys digital forensics evidence
| Action | What it costs you |
|---|---|
| Rebooting the machine | Memory is erased, which removes running processes, live connections and anything held only in RAM |
| Reimaging immediately | The fastest route back to working, and it destroys the answer to how they got in. The same route stays open |
| Investigating on the live system | Browsing files updates access times and overwrites deleted data. Work on a verified copy |
| Deleting the malicious account | Removes the record of what it did. Disable and preserve instead |
| Restoring from backup first | Overwrites the compromised state before anyone examined it, and may restore the original weakness |
| No record of who did what | Chain of custody breaks, and findings become arguable exactly when they need to be solid |
Every one of these is a reasonable instinct under pressure, which is why the sequence belongs in a written incident response plan rather than being decided at the time. Isolate the machine from the network, but leave it running.
Where Osto fits
Osto is not a digital forensics firm. There is no disk imaging service, no memory capture tooling and no expert witness engagement, and a serious breach still warrants a digital forensics specialist. What Osto affects is whether that specialist finds anything when they arrive.
Endpoint, identity, cloud, network and application events are retained in one SIEM rather than in five consoles with five different retention settings, which is usually the difference between a timeline that can be reconstructed and one that cannot. Endpoint detection records process execution and connections rather than only flagging known malware, so the account of what ran on a machine survives the event. Identity records show what was reached and when, which is what determines breach scope in a cloud environment.
That preparation also carries the compliance weight. The evidence-preservation and investigation expectations in SOC 2, ISO 27001 Annex A and HIPAA are about demonstrable capability, and the reporting clocks under the DPDP Act and CERT-In assume you can establish scope quickly. Neither is achievable if the logs expired.
Platform walkthrough
Have the logs when you need them
Endpoint, identity, cloud and application events retained and correlated in one SIEM, so scope can be established in hours rather than guessed at.
Book a demoEvidence from live controls · 200+ frameworks mapped · One platform, everything
Frequently asked questions
What is digital forensics?
The collection, preservation and analysis of evidence from systems in a way that withstands challenge. In security it establishes how an intrusion happened, what was accessed, what was taken and whether the attacker still has access.
What is the difference between digital forensics and incident response?
Incident response is the whole operation, including containment, recovery and communication. Forensics is the evidence discipline within it. Response is often under pressure to restore service, which is precisely what destroys forensic evidence, so the plan has to sequence them deliberately.
Should you shut down a compromised machine?
No. Powering off erases memory, which holds running processes, live connections and sometimes keys. Isolate it from the network and leave it running until someone has captured what is needed.
How long should logs be retained for forensics?
Longer than the time an intrusion is likely to go unnoticed, which is typically months rather than weeks. Identity, cloud audit and endpoint telemetry are the highest-value sources to extend first.
When do you need an external digital forensics firm?
When the breach is likely to be notifiable, when insurance or litigation is involved, when a regulator is asking, or when the attacker had privileged access. Insurers frequently mandate their own panel, so check the policy before appointing anyone.

