Platform

See how much of an attack you could reconstruct today.

Forensic Horizon sits above the SIEM, EDR, identity, network and cloud platforms you already own and answers one operational question: given the evidence that exists today, how much of a serious cyber incident could your investigators actually reconstruct, and how far back?

Forensic Horizon

30days

Target 90 days

Evidence coverage

79%

Critical assets

Evidence assurance

54%

E2 average

Forensic Horizon: Assurance DashboardExample Assessment
✓ Verified● In progress! Attention

Forensic Horizon

30days

Target 90 days

Critical Evidence Coverage

79%

12 of 57 sources partial

Ransomware Recon.

71%

10 stages evaluated

Evidence Assurance

54%

E2 average

Scenario reconstruction

Ransomware71%
Privileged Account Compromise64%
Microsoft 365 Compromise58%
Data Exfiltration41%
Evidence sourceRetentionAssurance
Firewall180 daysE3
Active Directory90 daysE2
EDR30 daysE2
DNS14 daysE1

Overview

Four measurement domains, one operating model.

Each measurement is traceable to an investigative question, and each investigative question is traceable to the evidence sources it depends upon. Nothing is scored without a stated dependency.
Domain 01

Evidence inventory

Every source that can contribute to an investigation, with owner, retention, accessibility, query path and assurance level.

Domain 02

Investigative question model

A structured library of the questions responders must answer per scenario, each mapped to required evidence.

Domain 03

Reconstruction analysis

Per-stage reconstruction capability, derived from evidence availability rather than tool inventory.

Domain 04

Change impact

Projected effect of retention, coverage or configuration changes on measured investigative capability.

Core metrics

Metrics that an engineering team can defend in a review.

MetricDefinitionUnitDerived from
Forensic HorizonHistorical period over which a scenario can reliably be reconstructedDaysRetention × coverage × assurance of required sources
Scenario ReconstructionShare of investigative questions answerable for a scenario%Question-level evidence availability
Critical Evidence CoverageShare of critical assets and sources producing usable evidence%Asset inventory × source telemetry
Evidence AssuranceDegree to which availability has been validated rather than assumed%E0-E4 assurance levels

Scenario reconstruction

Stage-level output, not a single score.

Reconstruction is reported per attack stage so remediation can be targeted at the stages where attribution is actually lost.

Scenario

Ransomware

Overall reconstruction

71%

Initial Access81%
Execution94%
Persistence76%
Privilege Escalation88%
Credential Access71%
Discovery63%
Lateral Movement57%
Collection43%
Exfiltration28%
Impact93%

Blind spots

Each finding names the consequence.

A blind spot is only useful if it states what an investigator will be unable to establish. Findings are written in those terms.

Investigative question

Was DCSync performed?

Partial capability

Evidence

  • Domain Controller Security LogsAvailable, 90 days, tested (E3)
  • Active Directory auditingDirectory service access auditing enabled
  • Endpoint process telemetryEDR detail retained 30 days only
  • Historical source-host telemetryNot retained beyond current EDR window

Investigative consequence

Identity attribution may be possible, but process-level attribution from the originating endpoint may be incomplete after 30 days.

Evidence sources

Source-level record for every dependency.

SourceCategoryRetentionAccessibilityAssuranceStatus
FirewallNetwork180 daysSIEM + archiveE3Verified
VPNNetwork365 daysSIEME3Verified
Active DirectoryIdentity90 daysSIEME2In progress
Entra IDIdentity30 daysNativeE2In progress
EDREndpoint30 daysNative consoleE2Attention
DHCPNetwork30 daysFile shareE1Attention
DNSNetwork14 daysPartialE1Attention

Evidence retention by source

Example Assessment
VPN365d
Firewall180d
Active Directory90d
EDR30d
DHCP30d
DNS14d

Current Forensic Horizon

30 days

Determined by the shortest retention among the evidence sources an investigation actually requires, not by the longest retention configured.

Why accessibility is scored separately

Evidence that exists in cold storage, in a system without a working query path, or under an owner outside the security organization is not evidence an incident response team can use within an investigation timeline. Accessibility is therefore recorded and scored independently of retention.

Improvement simulation

Model the change before the budget request.

Each candidate change is evaluated against the same measurement model, so its projected effect on investigative capability is comparable across proposals.

Current state

DNS retention
14 days
Forensic Horizon
30 days
Ransomware reconstruction
71%

Recommended change

Increase DNS retention

14 → 90 days

Single-source change; no additional log ingestion into the SIEM required.

Projected impact

Forensic Horizon
30 → 58 days
Ransomware reconstruction
71 → 76%

Projection based on measured dependencies.

Evidence assurance

How a capability was established is part of the record.

Every source carries an assurance level. Reported capability is weighted by it, so an untested assumption never reads the same as a tested query result.
LevelDefinitionBasis
E0Assertion onlyCapability is stated but not examined.
E1Documentation reviewedPolicy or configuration documentation examined.
E2ObservedEvidence availability observed in the platform.
E3Technically testedQueries executed against historical data.
E4DemonstratedDemonstrated during controlled investigation or reconstruction exercise.

Product direction

Continuous assurance

Designed to detect when environment change reduces investigative capability: new asset groups without telemetry, EDR agent coverage decline, retention policy changes, failed collectors, and migrations of critical systems.

Deployment model

  • On-premises deployment intended for security-sensitive environments.
  • Metadata-oriented model: evidence availability, coverage, retention and usability, not raw-log storage.
  • Role-based access, with assessment records and findings held inside the customer environment.
  • Export of findings and baselines for internal audit and management reporting.

Next step

Get more investigative value from the tools you already own.

A Forensic Horizon Assessment measures your current investigative reach, validates it technically, and names the changes that extend it.