Network Forensics
Definition
A sub-discipline of cyber forensics focused on capturing and analysing network traffic, packet captures, and flow records to reconstruct communications and identify attack sources or data exfiltration paths.
- Field
- Sub-discipline of cyber forensics
- Data sources
- Packet captures, flow records
- Goal
- Reconstruct communications
- Use
- Identify attack sources and exfiltration paths
Common questions
How does network forensics differ from host-based forensics?+
Network forensics examines traffic passing between systems, while host-based forensics examines artefacts left on a single device, such as its disk and memory.
Why is timely capture important in network forensics?+
Traffic is often not retained by default, so evidence can be permanently lost if packet or flow capture was not already running before the incident occurred.
Related terms
- Chain of Custody
- The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
- Cyber Forensics
- The branch of forensic science concerned with collecting, preserving, and analysing digital evidence from networked environments for use in legal proceedings. Covers...
- Indicator of Compromise (IoC)
- An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
- Mutual Legal Assistance Treaty (MLAT)
- A bilateral or multilateral treaty under which signatory states agree to assist each other in gathering evidence for criminal investigations. MLATs define...
- Order of Volatility
- The sequence in which digital evidence should be collected, ranked from most to least transient. Defined in RFC 3227. CPU registers and...