Digital Forensics
Digital forensics secures and investigates digital traces so an incident can be reconstructed and used as evidence.
Digital forensics is the legally sound preservation and analysis of digital evidence. After an incident, it clarifies what happened, how the attacker operated and which data was affected.
How it works
First, evidence is secured: memory, hard drives, logs, and cloud data. This process follows strict rules to keep the data unchanged and traceable. Experts then reconstruct the event timeline using timestamps, processes, files, and connections. The result is a timeline of the attack with evidence for each step.
For example, after a ransomware attack, a company wants to know if data was exfiltrated. The forensic analysis finds an archiving tool on a server and connections to cloud storage. The logs reveal the volume of data transferred. This helps the company decide if a report under the revFADP (revised Federal Act on Data Protection) is necessary.
What to look out for
- Secure evidence before systems are reinstalled.
- Memory contents are lost when a device is switched off. Isolation is often better than shutting down.
- Document who secured which pieces of evidence and when.
- Keep logs for long enough. Many attacks begin weeks before they are discovered.
- Clarify early if the findings will be used in court or for an insurance claim.
Switzerland and regulation
For criminal charges or civil proceedings, evidence must be secured in a traceable manner. Insurers also often require a forensic report. When handling employee data, the revFADP and employment law must be observed.
How it differs from Incident Response
Incident Response aims to stop an attack quickly and restore normal operations. Forensic analysis focuses on reconstructing the event completely and with supporting evidence. In practice, both run in parallel and must be well coordinated.
Typical mistakes
IT departments often delete traces with good intentions, for instance by reinstalling systems or running virus scans. Another common mistake is a lack of logs due to short retention periods.
How we implement it
In the SOC, we secure initial evidence during the containment phase. A full forensic investigation for a major incident is part of our separately billed Incident Response service.