Evidence-based reconstruction
Digital forensics applies controlled methods to identify, collect, preserve, examine, analyze, and report digital evidence. In incident response, the objective is to establish what happened, affected scope, attacker action, control failure, containment need, and recovery criteria with explicit uncertainty.
Sources and order
Plan for volatile memory, processes, connections, sessions, cloud state, identity events, gateway logs, application records, files, disks, snapshots, configuration, and backups. Collect volatile and short-retention data before it changes, when safe and authorized.
Record source system, owner, collection method, time, clock state, tool, hash or integrity method, access, storage, and every transfer. Keep originals protected and analyze verified copies.
Examination and analysis
Normalize time carefully and preserve original timestamps. Separate observed artifacts from interpretation. Correlate identity, session, process, network, policy, and application evidence. Test alternate explanations and gaps.
Document tool limitations, parsing errors, missing data, retention, tampering possibilities, and confidence. Repeat a critical result with an independent method when consequence requires it.
Failure and residual risk
Containment can destroy volatile evidence, and delayed containment can allow harm. Cloud and managed services can expose only provider-selected records. Logs can be incomplete, attacker-modified, time-skewed, or privacy-sensitive. A disk image does not capture external identity or cloud state.
Absence of evidence is not evidence of absence unless collection coverage and retention support that claim.
Pomerium boundary
Pomerium access logs can show covered identity, route, policy decision, and request context. They do not prove endpoint process activity, direct-origin requests, identity-provider administration, or final application-object action. Investigations must join independent sources and preserve the Pomerium configuration and log pipeline state.
Evaluation checklist
- Which volatile, short-retention, mutable, remote, and provider-controlled sources can answer the incident questions?
- Are original evidence, collection method, time, integrity, access, transfer, and analysis copies recorded?
- Does the timeline separate observed fact, inference, uncertainty, and missing coverage?
- Can containment preserve critical evidence without allowing unacceptable continued harm?
- Which conclusion depends on absent or unverified data and needs a narrower claim?
