Ablaufschema einer IT-forensischen Untersuchung in vier Stufen: Sichern des Arbeitsspeichers, Erstellen eines forensischen Images der Festplatte mit Prüfsumme, Auswertung von Protokolldateien, Aufbau einer Zeitleiste des Angriffs.

IT Forensics

IT forensics is the systematic examination of computers, phones, and networks following an attack or a crime. The goal is to secure and evaluate traces in such a way that they hold up later in court or in a report to management.

When a company is broken into, forensic investigators arrive. They photograph the crime scene, take fingerprints, and document every step. IT forensics does exactly that for computers, phones, servers, and networks. After an attack or data theft, experts examine the affected devices. They want to know: Who was in, when, by what route, and what did the person take or change? What matters is not just the result, but also that every step of the work is logged without gaps. Because only then will a finding later hold up in court or before an insurer.

What is lost without securing traces

After an attack, the first impulse is usually: wipe everything and start working again. That’s understandable, but risky. If you don’t know the cause, you don’t close the gap. Attackers then often come back within a few weeks via the same route. Forensics provides the answer to how the intrusion succeeded.

There is also a legal aspect. If personal data has been leaked, companies in Europe must report this to the supervisory authority, usually within 72 hours. This report requires solid statements about which data is affected. Cyber insurers, too, generally only pay out if a forensic report proves the damage. In such cases, an investigation without clean documentation is practically worthless.

A common misconception is confusing forensics with defense. Forensics does not prevent an attack. It only begins once something has happened, and it works backward into the past. It is more like an autopsy than a vaccination.

From the hard drive copy to the timeline

The first step is always securing, not examining. Experts create an exact copy of the storage medium, a so-called forensic image. Only this copy is worked with; the original remains untouched. So that no one can claim the copy was altered, a checksum is calculated. This is a long sequence of numbers that changes completely with the smallest change to the file.

Speed matters especially with working memory. This memory contains everything the computer is currently doing, but loses its contents when switched off. Passwords and active malware are often found only there. That’s why an order of volatility applies: secure first what disappears fastest, then hard drives and log files.

Evaluation afterward relies mainly on timestamps. Almost every action leaves an entry: a login in the system log, access to a file, an outbound connection in the firewall’s records. From these individual traces, forensics builds a timeline of the attack. Even deleted files can often still be reconstructed, because deletion usually just means the space was freed up for overwriting. Such a reconstruction is rarely complete, however, since skilled attackers deliberately clean up their tracks.

Ransomware cases, authorities, and the profession

IT forensics almost always appears in the news after major attacks involving ransomware. A hospital or a city administration is paralyzed, and the report states that external specialists are investigating the incident. That is exactly forensic work. The fact that authorities often provide no details for weeks is because the analysis itself takes that long.

The method is also used outside of hacking attacks. Police and prosecutors analyze seized phones. Companies investigate suspected cases of data theft by their own employees. Large corporations have their own teams for this, often called incident response, meaning response to security incidents. Smaller companies buy the service from providers, which quickly costs five-figure sums.

For the world of AI, the topic is becoming practically relevant right now. Attacks are increasingly automated, and analysis programs use pattern recognition to find anomalies among millions of log lines. But the assessment remains human work. A program can flag an anomaly, but responsibility for the conclusion still rests with the examiner.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.