Forensics - work at the crime scene
Securing evidence - work at the crime scene
How best to deduce the perpetrator and circumstances of the crime?
By examining the evidence of a crime during crime scene work. In the case of investigative authorities, this task is performed by the forensics team. In the case of IT security incidents, the CERT (Computer Emergency Response Team), including IT forensic experts, takes care of securing the evidence and cleaning up the systems. The classic activities of the SpuSi include searching for evidence, recording evidence and analysing evidence - no different from IT forensics.
How does forensics begin?
Always and truly always with securing the crime scene. For one reason: No new traces may be left and no existing traces may be contaminated. And this also applies to the "information systems" crime scene.
Don't make the IT forensics team's job harder than it has to be and don't try to retrace the traces of the attack yourself. Experiencing a security incident is nerve-wracking and you tend to want to do something about it. This is completely understandable. Therefore, if the worst comes to the worst, simply stick to the following recommendations. These will give you the feeling that you are making a meaningful contribution because you are actually doing it: you are securing the traces of the cyberattack, helping to rectify the incident and keeping your nervous hands busy at the same time.
How to properly cordon off the crime scene:
To cover up as little evidence of the cyberattack as possible, you should stick to a few "rules".
If you notice a security incident, don't panic, but stay calm. Panic is rarely a good advisor.
Suspend further work on the IT systems.
Report the security incident to a company that specialises in incident response, such as us, and request help. It is best to find answers to the following questions: What has happened? Which systems are affected? When did this happen? Where should the CERT be located?
Document your observations. All information is helpful for successful investigation and prevention of further attacks.
What evidence you can secure yourself:
To facilitate the work of CERTs, you can initiate the following measures yourself:
Preserve systems:
Switch off hardware systems and servers or pull out network plugs
Switch off virtual systems, hosted via Hyper-V or VMware, do not switch them off but isolate them from the network
Save relevant logs:
Firewall logs
Proxy access logs
Event logs
The latter are located under:
C:\Windows\System32\winevt\Logs in the format *.evtx.
Relevant here are events about:
Security
System
Application
Microsoft-Windows-Powershell/Operational
Microsoft-Windows-Powershell/Admin
Microsoft-Windows-CMBClient/Operational
Microsoft-Windows-RemoteConnectionManager/Operational
Microsoft-Windows-LocalSessionManager/Operational
Create a list of all existing/used systems with name and IP address:
Domain Controller
DNS-Server
Mail server
File server
Database server
Virus scanner management systems
Create a list of domain administrators
If available: A list of network segments
VPN network
DMZ
Production network
Client network
Server network
Finally, a word of advice: If you find viruses on your systems yourself, never upload them to portals such as VirusTotal.such as VirusTotal. Are you wondering why? If an attacker has developed the virus specifically for your company but has not yet launched its actual attack, then now is the time to do so. As soon as the virus has been published on the portal, the attacker will be aware of its discovery and may start encrypting it to cover their own tracks.

Ellen Leipelt
Marketing Specialist
Published on 17.05.2025
