← All ArticlesJune 9, 2026·5 min read

Digital Forensics After a Breach: Preserving Evidence, Building Cases

Published by the 0g0 research team

When a cyberattack occurs, the instinct of most organisations is to restore normal operations as quickly as possible. This is an understandable priority — operational continuity has real financial, reputational, and service delivery implications. But the rush to recovery, if not managed carefully, destroys the evidence needed to understand what happened, attribute the attack to specific actors, satisfy regulatory reporting requirements, and pursue legal remedies.

Digital forensics is the discipline of collecting, preserving, and analysing electronic evidence in a manner that maintains its integrity and legal admissibility. In the context of cyber incidents, it is the bridge between the technical event and the legal, regulatory, and insurance consequences that follow.

Why Forensic Integrity Matters

Evidence that has been improperly handled — modified, deleted, or collected without proper chain-of-custody documentation — may be inadmissible in criminal proceedings, civil litigation, or regulatory investigations. This has practical consequences:

Criminal prosecution of attackers requires evidence that can be presented in court. If the investigation that might have supported prosecution was conducted without forensic discipline, the evidence may not meet legal standards. Attackers who would otherwise be prosecuted go free.

Insurance claims require forensic evidence of the scope and nature of the breach. Insurers routinely deny claims where policyholders cannot demonstrate with forensic evidence what data was exfiltrated, which systems were compromised, and when the breach occurred. Without proper forensics, the insured recovers nothing — or recovers far less than their actual losses.

Regulatory investigations — by OCR for HIPAA breaches, by state attorneys general under breach notification laws, by SEC for securities law implications — require organisations to demonstrate what happened with documented evidence. Organisations that cannot reconstruct the incident timeline with forensic evidence face the worst-case regulatory outcomes.

Civil litigation against either the attackers or the target organisation requires evidence that meets civil discovery standards. A class action lawsuit by breach victims, or a suit against a vendor whose software was the attack vector, both depend on forensic evidence.

The Evidence Lifecycle: From Incident to Courtroom

Forensically sound incident response follows a disciplined process:

Evidence identification: Before any collection begins, the scope of potentially relevant evidence must be defined. This includes affected systems (workstations, servers, network devices), supporting infrastructure (authentication systems, email systems, cloud platforms), and indirect evidence (badge access logs, physical security footage, telephone records).

Evidence preservation: Volatile evidence — data held in RAM, running processes, network connections — must be captured before systems are shut down or rebooted. Disk images — bit-for-bit copies of storage media — must be created before any analysis begins. The original media is preserved unchanged; analysis proceeds on working copies.

Chain of custody: Every piece of evidence must be logged from the moment of collection: what was collected, by whom, at what time, from where, and every subsequent access to or transfer of that evidence. Chain of custody documentation must be comprehensive enough to demonstrate in court that the evidence has not been tampered with.

Cryptographic verification: Disk images and other collected evidence are cryptographically hashed (typically SHA-256) immediately upon collection. Any subsequent analysis must produce the same hash, demonstrating that the evidence has not been modified.

Analysis: Forensic analysis of collected evidence reconstructs the attack timeline, identifies entry points, traces lateral movement, and recovers evidence of attacker activity including files created, commands executed, and data accessed or exfiltrated.

Documentation: Findings are documented in formal reports suitable for regulatory submission, insurance claims, and legal proceedings. Forensic reports must be reproducible — another qualified examiner reviewing the same evidence using the same methodology should reach the same conclusions.

The First Responder's Critical Role

The most consequential decisions for forensic integrity are made in the first hours of incident response by the first responders — often internal IT staff who may not have forensic training. Common mistakes that compromise evidence:

Rebooting affected systems: Rebooting clears volatile memory, destroying evidence of running malicious processes. Affected systems should be isolated from the network but kept running until memory can be captured.

Running antivirus scans on affected systems: Antivirus software modifies files — quarantining, deleting, or altering malicious files — before they can be preserved and analysed. This is precisely backwards from what forensic investigation requires.

Remediation before evidence collection: Reformatting drives, reinstalling operating systems, or restoring from backup before forensic images have been collected permanently destroys evidence.

Inadequate logging: Many incidents are discovered to have inadequate logging to reconstruct the attack timeline because logs were not retained, were not comprehensive enough, or were themselves deleted by the attacker. Logging configuration is a forensic preparedness issue that must be addressed before an incident occurs.

Attributing Attacks to Specific Actors

Digital forensic investigation can in many cases identify the specific threat actor responsible for a cyber incident with high confidence. The techniques used:

Malware analysis: Custom malware used in targeted attacks often contains code elements, infrastructure references, and operational characteristics that link it to specific known threat actors. Many nation-state threat actors have signature techniques that the intelligence community has documented over years of analysis.

Infrastructure analysis: Command-and-control servers, domain registrations, and network infrastructure used in attacks are often shared across multiple incidents by the same actors. Identification of attacker-controlled infrastructure in an incident often connects it to previously attributed campaigns.

Tactics, Techniques, and Procedures (TTPs): How an attacker operates — the sequence of steps they follow, the tools they use, the mistakes they make — creates patterns that can identify the actor across multiple incidents even when specific technical indicators have changed.

Attribution findings can support law enforcement referrals, sanctions designations, and diplomatic actions against state-sponsored threat actors.

Forensics as a Leadership Tool

Beyond its legal and regulatory functions, forensic investigation is an essential leadership tool. The forensic report from a cyber incident should answer the questions that leadership and the board will demand: How did the attacker get in? What did they access or take? How long were they in the environment? What was the full scope of impact?

Without forensics, organisations are left with incomplete information, making it impossible to give stakeholders accurate answers, to prioritise remediation correctly, or to demonstrate to insurers and regulators the full (and bounded) scope of the incident.

0g0 Aegis maintains a digital forensics practice with certified forensic examiners (GCFE, GCFA, EnCE) who conduct cyber incident investigations to court-admissible standards. Our forensic reports are designed for regulatory submission, insurance claims, law enforcement cooperation, and civil litigation support. We are engaged at the outset of significant incidents to ensure that evidence is preserved from the first response action forward.

Need a product briefing?

Talk about the 0g0 Appliance for your environment — available now. Services are light support as the practice grows.

Request a Briefing

Free Assessment Tools

Test your own security posture with our free tools — no account required.

Explore free tools
Next step

Protect your organisation

Request a briefing on the 0g0 Appliance. Research is context — the product conversation is next.

Request a Briefing