Evidence inventory
Every source that can contribute to an investigation, with owner, retention, accessibility, query path and assurance level.
Platform
Forensic Horizon sits above the SIEM, EDR, identity, network and cloud platforms you already own and answers one operational question: given the evidence that exists today, how much of a serious cyber incident could your investigators actually reconstruct, and how far back?
Forensic Horizon
30days
Target 90 days
Evidence coverage
79%
Critical assets
Evidence assurance
54%
E2 average
CYBER EVIDENCE
Forensic Horizon
30days
Target 90 days
Critical Evidence Coverage
79%
12 of 57 sources partial
Ransomware Recon.
71%
10 stages evaluated
Evidence Assurance
54%
E2 average
Scenario reconstruction
| Evidence source | Retention | Assurance |
|---|---|---|
| Firewall | 180 days | E3 |
| Active Directory | 90 days | E2 |
| EDR | 30 days | E2 |
| DNS | 14 days | E1 |
Overview
Every source that can contribute to an investigation, with owner, retention, accessibility, query path and assurance level.
A structured library of the questions responders must answer per scenario, each mapped to required evidence.
Per-stage reconstruction capability, derived from evidence availability rather than tool inventory.
Projected effect of retention, coverage or configuration changes on measured investigative capability.
Core metrics
| Metric | Definition | Unit | Derived from |
|---|---|---|---|
| Forensic Horizon | Historical period over which a scenario can reliably be reconstructed | Days | Retention × coverage × assurance of required sources |
| Scenario Reconstruction | Share of investigative questions answerable for a scenario | % | Question-level evidence availability |
| Critical Evidence Coverage | Share of critical assets and sources producing usable evidence | % | Asset inventory × source telemetry |
| Evidence Assurance | Degree to which availability has been validated rather than assumed | % | E0-E4 assurance levels |
Scenario reconstruction
Scenario
Ransomware
Overall reconstruction
71%
Blind spots
Investigative question
Was DCSync performed?
Evidence
Investigative consequence
Identity attribution may be possible, but process-level attribution from the originating endpoint may be incomplete after 30 days.
Evidence sources
| Source | Category | Retention | Accessibility | Assurance | Status |
|---|---|---|---|---|---|
| Firewall | Network | 180 days | SIEM + archive | E3 | Verified |
| VPN | Network | 365 days | SIEM | E3 | Verified |
| Active Directory | Identity | 90 days | SIEM | E2 | In progress |
| Entra ID | Identity | 30 days | Native | E2 | In progress |
| EDR | Endpoint | 30 days | Native console | E2 | Attention |
| DHCP | Network | 30 days | File share | E1 | Attention |
| DNS | Network | 14 days | Partial | E1 | Attention |
Evidence retention by source
Example AssessmentCurrent Forensic Horizon
30 days
Determined by the shortest retention among the evidence sources an investigation actually requires, not by the longest retention configured.
Why accessibility is scored separately
Evidence that exists in cold storage, in a system without a working query path, or under an owner outside the security organization is not evidence an incident response team can use within an investigation timeline. Accessibility is therefore recorded and scored independently of retention.
Improvement simulation
Current state
Recommended change
Increase DNS retention
14 → 90 days
Single-source change; no additional log ingestion into the SIEM required.
Projected impact
Projection based on measured dependencies.
Evidence assurance
| Level | Definition | Basis |
|---|---|---|
| E0 | Assertion only | Capability is stated but not examined. |
| E1 | Documentation reviewed | Policy or configuration documentation examined. |
| E2 | Observed | Evidence availability observed in the platform. |
| E3 | Technically tested | Queries executed against historical data. |
| E4 | Demonstrated | Demonstrated during controlled investigation or reconstruction exercise. |
Product direction
Deployment model
Next step
A Forensic Horizon Assessment measures your current investigative reach, validates it technically, and names the changes that extend it.