Resources
Technical notes on cyber evidence assurance
Practitioner-oriented material on evidence coverage, retention, scenario reconstruction and investigative capability. Articles are published as they are completed.
Index
Articles
- 01
365 Days of Logs Does Not Mean 365 Days of Investigative Capability
Why aggregate retention figures overstate what an investigation can establish, and how the shortest load-bearing source sets the limit.
Evidence retentionIn preparation - 02
What Is a Forensic Horizon?
Definition, calculation method, and why the measurement is scenario-specific rather than a single organizational number.
MethodologyAvailable - 03
The 50 Questions Your SOC Must Be Able to Answer During Ransomware
A structured question set covering initial access, execution, credential access, lateral movement, exfiltration and impact.
Incident responseIn preparation - 04
Why EDR Coverage Is Not the Same as Forensic Readiness
Agent deployment percentages, retained process detail and field fidelity are three different measurements with three different consequences.
EndpointIn preparation - 05
From Log Collection to Cyber Evidence Assurance
Moving from a collection-oriented programme to one that validates whether required evidence is available, accessible and usable.
ProgrammeIn preparation
Articles marked “in preparation” are not yet published. No publication dates are shown until an article is available.
Prefer a measurement over a reading list?
A Forensic Horizon Assessment applies this methodology directly to your environment.