{"id":1223,"date":"2026-09-13T20:16:50","date_gmt":"2026-09-13T20:16:50","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1223"},"modified":"2026-09-13T20:16:50","modified_gmt":"2026-09-13T20:16:50","slug":"digital-forensics","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/digital-forensics\/","title":{"rendered":"Digital Forensics"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: DIGITAL FORENSICS\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">The outcome of a digital forensics investigation is decided months before the incident, by what you were recording and how long you kept it.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Operations<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Digital forensics is the disciplined collection, preservation and analysis of evidence from systems, in a way that holds up when someone challenges it. In a breach it answers how the attacker got in, what they reached, what left the building and whether they are still there. Everything it can tell you depends on data that existed before anyone knew there was a problem.<\/p>\n<\/div>\n\n<p>That constraint is why digital forensics is a preparation exercise far more than a response one.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#answers\">The four questions digital forensics answers<\/a><\/li>\n    <li><a href=\"#phases\">The four digital forensics phases<\/a><\/li>\n    <li><a href=\"#retention\">Retention decides the outcome<\/a><\/li>\n    <li><a href=\"#mistakes\">What destroys digital forensics evidence<\/a><\/li>\n    <li><a href=\"#osto\">Where Osto fits<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"answers\">The four questions digital forensics answers<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Question<\/th><th>Why it matters<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>How did they get in<\/td><td>Until the entry route is known, closing it is guesswork and reinfection is likely<\/td><\/tr>\n    <tr><td>What did they reach<\/td><td>Determines the scope of the breach and, in most jurisdictions, whether notification is required at all<\/td><\/tr>\n    <tr><td>What left<\/td><td>Regulators and customers ask what data was taken. Not knowing is usually treated as the worst answer<\/td><\/tr>\n    <tr><td>Are they still here<\/td><td>The question that decides whether you can safely resume operations, and the one most often answered too early<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"phases\" class=\"c-sage\">The four digital forensics phases<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 176\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Four forensic phases, identify, preserve, analyse and report, with chain of custody running beneath all of them.\">\n  <defs><marker id=\"df\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"14\" y=\"22\" width=\"164\" height=\"60\" rx=\"12\" fill=\"#e2eff7\"\/>\n  <text x=\"96\" y=\"47\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6f96\">Identify<\/text>\n  <text x=\"96\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Where evidence exists<\/text>\n  <line x1=\"182\" y1=\"52\" x2=\"204\" y2=\"52\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#df)\"\/>\n\n  <rect x=\"212\" y=\"22\" width=\"164\" height=\"60\" rx=\"12\" fill=\"#e3f0e9\"\/>\n  <text x=\"294\" y=\"47\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">Preserve<\/text>\n  <text x=\"294\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Copy without altering<\/text>\n  <line x1=\"380\" y1=\"52\" x2=\"402\" y2=\"52\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#df)\"\/>\n\n  <rect x=\"410\" y=\"22\" width=\"164\" height=\"60\" rx=\"12\" fill=\"#efe4f0\"\/>\n  <text x=\"492\" y=\"47\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#6b4576\">Analyse<\/text>\n  <text x=\"492\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Build the timeline<\/text>\n  <line x1=\"578\" y1=\"52\" x2=\"600\" y2=\"52\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#df)\"\/>\n\n  <rect x=\"608\" y=\"22\" width=\"138\" height=\"60\" rx=\"12\" fill=\"#cfd5f2\"\/>\n  <text x=\"677\" y=\"47\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#1c267a\">Report<\/text>\n  <text x=\"677\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Findings that hold<\/text>\n\n  <rect x=\"14\" y=\"98\" width=\"732\" height=\"58\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"122\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Chain of custody runs underneath all four.<\/text>\n  <text x=\"380\" y=\"141\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#a2603a\">Who touched what, when, and how it was verified unchanged. Break it and the findings are contestable.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<p>Preservation is the phase that goes wrong. Investigating a live system changes it, so the working copy must be taken first and verified against the original by hash. Everything after that runs on the copy.<\/p>\n\n<h2 id=\"retention\" class=\"c-plum\">Retention decides the outcome<\/h2>\n\n<p>Every digital forensics engagement runs into the same wall. An investigator can only reconstruct what was written down. Default retention on most sources is shorter than the time attackers typically remain undetected, which is why so many investigations end without an answer.<\/p>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Evidence source<\/th><th>What it proves, and the catch<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Identity and sign-in logs<\/td><td>The most valuable source in a cloud breach. Free tiers of most providers keep them for a matter of weeks<\/td><\/tr>\n    <tr><td>Cloud audit trails<\/td><td>Records API calls and configuration changes, but only if the trail was switched on before the incident and written somewhere the attacker could not reach<\/td><\/tr>\n    <tr><td>Endpoint telemetry<\/td><td>Process execution and network connections. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">Endpoint detection<\/a> keeps this. Plain <a href=\"https:\/\/www.osto.one\/resources\/glossary\/epp\/\">antivirus<\/a> does not<\/td><\/tr>\n    <tr><td>Email logs<\/td><td>Shows what was accessed, forwarded or exported. Retention varies sharply by licence tier<\/td><\/tr>\n    <tr><td>Network flow records<\/td><td>Reveals volume leaving and where it went. Rarely retained by default anywhere<\/td><\/tr>\n    <tr><td>Memory<\/td><td>Running processes, live connections, keys and unencrypted data. Gone the moment the machine is powered off<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Extend retention before you need it, not after<\/p>\n  <p>Intrusions are frequently discovered months after they begin, and a ninety-day log window investigated on day one hundred and twenty produces a report that says the entry point could not be determined. That sentence in a customer notification is worse than the breach. Longer retention on identity, cloud audit and endpoint telemetry is the cheapest digital forensics investment available, and it has to be bought before anything happens because logs cannot be created retrospectively.<\/p>\n<\/div>\n\n<h2 id=\"mistakes\" class=\"c-sky\">What destroys digital forensics evidence<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Action<\/th><th>What it costs you<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Rebooting the machine<\/td><td>Memory is erased, which removes running processes, live connections and anything held only in RAM<\/td><\/tr>\n    <tr><td>Reimaging immediately<\/td><td>The fastest route back to working, and it destroys the answer to how they got in. The same route stays open<\/td><\/tr>\n    <tr><td>Investigating on the live system<\/td><td>Browsing files updates access times and overwrites deleted data. Work on a verified copy<\/td><\/tr>\n    <tr><td>Deleting the malicious account<\/td><td>Removes the record of what it did. Disable and preserve instead<\/td><\/tr>\n    <tr><td>Restoring from backup first<\/td><td>Overwrites the compromised state before anyone examined it, and may restore the original weakness<\/td><\/tr>\n    <tr><td>No record of who did what<\/td><td>Chain of custody breaks, and findings become arguable exactly when they need to be solid<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Every one of these is a reasonable instinct under pressure, which is why the sequence belongs in a written <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">incident response<\/a> plan rather than being decided at the time. Isolate the machine from the network, but leave it running.<\/p>\n\n<h2 id=\"osto\">Where Osto fits<\/h2>\n\n<p>Osto is not a digital forensics firm. There is no disk imaging service, no memory capture tooling and no expert witness engagement, and a serious breach still warrants a digital forensics specialist. What Osto affects is whether that specialist finds anything when they arrive.<\/p>\n\n<p>Endpoint, identity, cloud, network and application events are retained in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">one SIEM<\/a> rather than in five consoles with five different retention settings, which is usually the difference between a timeline that can be reconstructed and one that cannot. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">Endpoint detection<\/a> records process execution and connections rather than only flagging known malware, so the account of what ran on a machine survives the event. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">Identity records<\/a> show what was reached and when, which is what determines breach scope in a cloud environment.<\/p>\n\n<p>That preparation also carries the compliance weight. The evidence-preservation and investigation expectations in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">ISO 27001 Annex A<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/hipaa\/\">HIPAA<\/a> are about demonstrable capability, and the reporting clocks under <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">the DPDP Act<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/guides\/cert-in-incident-reporting\/\">CERT-In<\/a> assume you can establish scope quickly. Neither is achievable if the logs expired.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Have the logs when you need them<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Endpoint, identity, cloud and application events retained and correlated in one SIEM, so scope can be established in hours rather than guessed at.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Evidence from live controls &middot; 200+ frameworks mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is digital forensics?<\/summary>\n  <p>The collection, preservation and analysis of evidence from systems in a way that withstands challenge. In security it establishes how an intrusion happened, what was accessed, what was taken and whether the attacker still has access.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between digital forensics and incident response?<\/summary>\n  <p><a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">Incident response<\/a> is the whole operation, including containment, recovery and communication. Forensics is the evidence discipline within it. Response is often under pressure to restore service, which is precisely what destroys forensic evidence, so the plan has to sequence them deliberately.<\/p>\n<\/details>\n\n<details>\n  <summary>Should you shut down a compromised machine?<\/summary>\n  <p>No. Powering off erases memory, which holds running processes, live connections and sometimes keys. Isolate it from the network and leave it running until someone has captured what is needed.<\/p>\n<\/details>\n\n<details>\n  <summary>How long should logs be retained for forensics?<\/summary>\n  <p>Longer than the time an intrusion is likely to go unnoticed, which is typically months rather than weeks. Identity, cloud audit and endpoint telemetry are the highest-value sources to extend first.<\/p>\n<\/details>\n\n<details>\n  <summary>When do you need an external digital forensics firm?<\/summary>\n  <p>When the breach is likely to be notifiable, when insurance or litigation is involved, when a regulator is asking, or when the attacker had privileged access. Insurers frequently mandate their own panel, so check the policy before appointing anyone.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">Incident Response<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">EDR<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/xdr\/\">XDR<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soar\/\">SOAR<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/threat-intelligence\/\">Threat Intelligence<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">IAM<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The outcome of a digital forensics investigation is decided months before the incident, by what you were recording and how\u2026<\/p>\n","protected":false},"author":8,"featured_media":1224,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[625,626],"class_list":["post-1223","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-digital-forensics","tag-digital-forensics-vs-incident-response"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1223","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1223"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1223\/revisions"}],"predecessor-version":[{"id":1225,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1223\/revisions\/1225"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1224"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1223"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1223"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1223"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}