Forensic Analysis

What is Forensic Analysis?

Forensic analysis is the process of searching log, flow, vulnerability and other security data to find the root cause of what, what, when, where, how and why of an issue or activity, or incident. Forensic analysis helps a security professional identify any unusual activity or suspicious user behavior.

Why Does Forensic Analysis Matter?

Many of today’s cyber attacks are designed to evade signature- and rule-based defenses, such as anti-virus and intrusion detection systems (IDS). Audit logs are often the only evidence of a successful data breach. Forensic analysis is critical to the detection and prevention of cyber attacks and is important in any dispute involving digitally stored evidence.

Key applications of forensic analysis include:

  • Analyzing the root cause of failed or compromised computer systems
  • Identifying who is responsible for policy violations or improper use of the network
  • Detecting advanced persistent attacks (APTs) in progress
  • Determining how far malware has spread to quarantine and clean affected systems
  • Providing evidence in a legal case that involves the use or misuse of computer systems

