An overview of network evidence
There are network log sources that can provide CSIRT personnel and incident responders with good information. Each network device provides different evidence based on its manufacturer and model. As a preparation task, CSIRT personnel should become familiar with how to access these devices to obtain the necessary evidence or have existing communication structures in place to engage IT personnel to assist with the proper response techniques during an incident.
Network devices such as switches, routers, and firewalls also have their own internal logs that maintain data on who accessed the device and made changes. Incident responders should become familiar with the types of network devices on their organization’s network and be able to access these logs in the event of an incident:
- Switches: These are spread throughout a network through a combination of core switches that handle traffic from a range of network segments and edge switches...