Terminology Index

Glossary

1801 terms

Open concept maps

Showing 609-640 of 1801 terms

E
32

Evidence Collection

Gathering and preserving the data that supports an investigation, logs, artifacts, screenshots, and records, in a sound, documented way so it accurately reflects what happened and can support decisions or later review.

During triage and investigation, an analyst collects the evidence that backs their conclusions: relevant log entries, host artifacts, network records, and screenshots, attached to the case. Doing this carefully, preserving originals, recording where and when evidence came from, ensures the investigation is accurate and defensible, supports handoffs and escalation, and lays the groundwork should the case become a formal incident with legal weight.

Introduced in: SOC Analyst Fundamentals

Examples

  • Capturing the relevant log entries that support an alert's disposition.
  • Attaching host artifacts and screenshots to an investigation case.
  • Preserving original evidence and recording its source during triage.

No related terms linked yet.