Terminology Index

Glossary

1801 terms

Open concept maps

Showing 1089-1120 of 1801 terms

N
17

Network Evidence

Evidence collected from network sources, logs, captures, flow data, IDS alerts, that defenders use to investigate incidents and prove what happened on the wire. It is a core form of incident evidence.

Network evidence includes packet captures, flow records, DNS and proxy logs, firewall logs, IDS alerts, and any other recordings of network activity. Defenders rely on it to reconstruct intrusions, understand attacker infrastructure, and verify findings. Sound handling, ensuring integrity, capturing enough detail, and preserving for the necessary time, is essential, and network evidence often pairs with host evidence to build a full picture of an incident.

Introduced in: Networking Foundations

Examples

  • Using flow records to trace which hosts an attacker contacted.
  • Capturing packet data to reconstruct an exfiltration event.
  • Combining network and host evidence to verify an investigation's findings.

No related terms linked yet.

O
15