Digital Forensics

Digital forensics phases and chain of custody

The outcome of a digital forensics investigation is decided months before the incident, by what you were recording and how long you kept it.

  • Glossary
  • Operations

The short answer

Digital forensics is the disciplined collection, preservation and analysis of evidence from systems, in a way that holds up when someone challenges it. In a breach it answers how the attacker got in, what they reached, what left the building and whether they are still there. Everything it can tell you depends on data that existed before anyone knew there was a problem.

That constraint is why digital forensics is a preparation exercise far more than a response one.

The four questions digital forensics answers

QuestionWhy it matters
How did they get inUntil the entry route is known, closing it is guesswork and reinfection is likely
What did they reachDetermines the scope of the breach and, in most jurisdictions, whether notification is required at all
What leftRegulators and customers ask what data was taken. Not knowing is usually treated as the worst answer
Are they still hereThe question that decides whether you can safely resume operations, and the one most often answered too early

The four digital forensics phases

Identify Where evidence exists Preserve Copy without altering Analyse Build the timeline Report Findings that hold Chain of custody runs underneath all four. Who touched what, when, and how it was verified unchanged. Break it and the findings are contestable.

Preservation is the phase that goes wrong. Investigating a live system changes it, so the working copy must be taken first and verified against the original by hash. Everything after that runs on the copy.

Retention decides the outcome

Every digital forensics engagement runs into the same wall. An investigator can only reconstruct what was written down. Default retention on most sources is shorter than the time attackers typically remain undetected, which is why so many investigations end without an answer.

Evidence sourceWhat it proves, and the catch
Identity and sign-in logsThe most valuable source in a cloud breach. Free tiers of most providers keep them for a matter of weeks
Cloud audit trailsRecords API calls and configuration changes, but only if the trail was switched on before the incident and written somewhere the attacker could not reach
Endpoint telemetryProcess execution and network connections. Endpoint detection keeps this. Plain antivirus does not
Email logsShows what was accessed, forwarded or exported. Retention varies sharply by licence tier
Network flow recordsReveals volume leaving and where it went. Rarely retained by default anywhere
MemoryRunning processes, live connections, keys and unencrypted data. Gone the moment the machine is powered off

Extend retention before you need it, not after

Intrusions are frequently discovered months after they begin, and a ninety-day log window investigated on day one hundred and twenty produces a report that says the entry point could not be determined. That sentence in a customer notification is worse than the breach. Longer retention on identity, cloud audit and endpoint telemetry is the cheapest digital forensics investment available, and it has to be bought before anything happens because logs cannot be created retrospectively.

What destroys digital forensics evidence

ActionWhat it costs you
Rebooting the machineMemory is erased, which removes running processes, live connections and anything held only in RAM
Reimaging immediatelyThe fastest route back to working, and it destroys the answer to how they got in. The same route stays open
Investigating on the live systemBrowsing files updates access times and overwrites deleted data. Work on a verified copy
Deleting the malicious accountRemoves the record of what it did. Disable and preserve instead
Restoring from backup firstOverwrites the compromised state before anyone examined it, and may restore the original weakness
No record of who did whatChain of custody breaks, and findings become arguable exactly when they need to be solid

Every one of these is a reasonable instinct under pressure, which is why the sequence belongs in a written incident response plan rather than being decided at the time. Isolate the machine from the network, but leave it running.

Where Osto fits

Osto is not a digital forensics firm. There is no disk imaging service, no memory capture tooling and no expert witness engagement, and a serious breach still warrants a digital forensics specialist. What Osto affects is whether that specialist finds anything when they arrive.

Endpoint, identity, cloud, network and application events are retained in one SIEM rather than in five consoles with five different retention settings, which is usually the difference between a timeline that can be reconstructed and one that cannot. Endpoint detection records process execution and connections rather than only flagging known malware, so the account of what ran on a machine survives the event. Identity records show what was reached and when, which is what determines breach scope in a cloud environment.

That preparation also carries the compliance weight. The evidence-preservation and investigation expectations in SOC 2, ISO 27001 Annex A and HIPAA are about demonstrable capability, and the reporting clocks under the DPDP Act and CERT-In assume you can establish scope quickly. Neither is achievable if the logs expired.

Platform walkthrough

Have the logs when you need them

Endpoint, identity, cloud and application events retained and correlated in one SIEM, so scope can be established in hours rather than guessed at.

Book a demo

Evidence from live controls · 200+ frameworks mapped · One platform, everything

Frequently asked questions

What is digital forensics?

The collection, preservation and analysis of evidence from systems in a way that withstands challenge. In security it establishes how an intrusion happened, what was accessed, what was taken and whether the attacker still has access.

What is the difference between digital forensics and incident response?

Incident response is the whole operation, including containment, recovery and communication. Forensics is the evidence discipline within it. Response is often under pressure to restore service, which is precisely what destroys forensic evidence, so the plan has to sequence them deliberately.

Should you shut down a compromised machine?

No. Powering off erases memory, which holds running processes, live connections and sometimes keys. Isolate it from the network and leave it running until someone has captured what is needed.

How long should logs be retained for forensics?

Longer than the time an intrusion is likely to go unnoticed, which is typically months rather than weeks. Identity, cloud audit and endpoint telemetry are the highest-value sources to extend first.

When do you need an external digital forensics firm?

When the breach is likely to be notifiable, when insurance or litigation is involved, when a regulator is asking, or when the attacker had privileged access. Insurers frequently mandate their own panel, so check the policy before appointing anyone.