Corroboration
Definition
The practice of confirming an observed attacker action by finding evidence of the same action in at least two independent data sources, for example, a suspicious process in EDR telemetry confirmed by a corresponding outbound connection in network flow data. Corroboration reduces the risk of acting on a single-source false positive during scoping.
- Requirement
- Same action confirmed in 2+ independent data sources
- Example pairing
- EDR process telemetry plus network flow data
- Purpose
- Reduces risk of acting on single-source false positive
- Applies during
- Incident scoping and confirmation
Common questions
Why is corroboration especially important during the scoping phase of an incident?+
Scoping decisions, such as which hosts to isolate or preserve, are often made under time pressure with incomplete data, so confirming a suspected attacker action across two independent telemetry sources reduces the chance of committing containment resources based on a single tool's false alarm.
What counts as truly independent data sources for corroboration purposes?+
Sources are independent when a failure or blind spot in one does not also affect the other, such as endpoint telemetry and network flow logs collected by separate systems, whereas two alerts generated by the same detection engine from the same log feed do not provide real corroboration.
How does corroboration in incident response compare to corroboration of a witness account?+
Both rely on the same logic of seeking independent confirmation to reduce reliance on a single fallible source, though incident response corroboration draws on machine-generated telemetry while witness corroboration draws on separate human accounts or physical evidence.
Related terms
- Bharatiya Sakshya Adhiniyam 2023 (BSA)
- India's current evidence statute, which replaced the Indian Evidence Act 1872. Section 63 of the BSA governs electronic records and requires a...
- Blast Radius
- The full set of systems, accounts, and data that an attacker has accessed or could access given their current level of compromise....
- Declaration Threshold
- The criteria defined in an organisation's IR plan that a suspected event must meet before it is formally declared a confirmed incident,...
- Dwell Time
- The period between an attacker gaining initial access and their detection. Reducing dwell time is a primary goal of threat hunting. The...
- Gatekeeping
- The judicial function, codified in the United States by Daubert v. Merrell Dow Pharmaceuticals (1993) and Federal Rule of Evidence 702, of...
- General Acceptance (Frye Standard)
- The admissibility rule from Frye v. United States (DC Cir. 1923) requiring a technique to be generally accepted in the relevant scientific...
- Initial Indicator of Compromise (IoC)
- The first observable artefact or event that triggers the investigation: a hash match, a suspicious process, an anomalous login, or an alert...
- Lateral Movement
- Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
- Opinion Evidence
- Testimony about an inference or conclusion drawn from facts, rather than direct observation. Expert opinion is a recognised exception to the general...
- Voir Dire (On Evidence)
- A preliminary hearing, conducted in the absence of the jury, at which the judge evaluates the admissibility of proposed expert evidence. The...
Explained in these topics
- Landmark Judgments on Expert EvidenceEvidence that confirms or supports a piece of evidence from an independent source. In Indian jurisprudence, expert opinion is treated as requiring corroboratio...
- Scoping and Confirming an Incident