Terminology Index

Glossary

64 terms starting with "E"

Open concept maps

Showing 33-64 of 64 terms

E
32

Evidence Collection

Gathering and preserving the data that supports an investigation, logs, artifacts, screenshots, and records, in a sound, documented way so it accurately reflects what happened and can support decisions or later review.

During triage and investigation, an analyst collects the evidence that backs their conclusions: relevant log entries, host artifacts, network records, and screenshots, attached to the case. Doing this carefully, preserving originals, recording where and when evidence came from, ensures the investigation is accurate and defensible, supports handoffs and escalation, and lays the groundwork should the case become a formal incident with legal weight.

Introduced in: SOC Analyst Fundamentals

Examples

  • Capturing the relevant log entries that support an alert's disposition.
  • Attaching host artifacts and screenshots to an investigation case.
  • Preserving original evidence and recording its source during triage.

No related terms linked yet.