Scaling forensic evidence collection
When we talk about enterprise-wide data collection, the first thing that probably comes to mind is security controls. There are many security controls that can provide valuable data for incident investigation. However, it is important to remember that security controls’ storage is limited. EDRs usually store telemetry for between one week and several months. Again, not all solutions presented on the market provide proper telemetry collection capabilities or indexing and search options depending on the licensing and solution architecture. We will perform a deep dive into telemetry analysis and its enrichment techniques for incident investigation and threat hunting in the following chapters.
Security Information and Event Management (SIEM), or log management systems, collect and index logs acquired from the different configured data sources for anywhere between one month to one year based on the licensing. These solutions should guarantee...