Professional IT services from accompio for companies in Germany.
Blog

Digital Forensics in Incident Response: Securing Traces, Understanding Attacks, Deriving Measures

10.07.2026

A cyber attack is only truly overcome when companies can understand how the attacker proceeded. This is precisely where digital forensics lays the foundation for sustainable security measures.

Mann talks about IT services at Accompio in a webinar.

A successful cyber attack raises many questions: How did the attacker gain access to the company? Which systems were affected? Which data did the attacker compromise? And above all: Is there a risk that the incident will be repeated?

Digital forensics provides the answers. It is a central component of professional incident response and helps to systematically reconstruct attacks, secure evidence and derive effective measures for the future.

In an interview, Thomas Ringhof explains how forensic analyses are carried out in practice, what mistakes companies should avoid in an emergency, and why successful incident response goes far beyond mere damage limitation.

The most important points briefly

  • Digital forensics is a central component of incident response. This helps to not only contain attacks but also to fully understand their cause, progression and impact.
  • Security incidents are noticeably increasing. r-tec, part of the accompio The corporate group handled around 80 security incidents in 2024. By 2025, the number had already risen to over 130 cases per year.
  • The better the forensic evidence, the more well-founded the analysis. Logs, memory dumps, network data, and endpoints provide the basis for reconstructing the attack chain and making robust decisions.
  • Forensic insights form the basis for sustainable security measures. Effective countermeasures can only be derived once initial access, propagation, and persistence mechanisms are understood.
  • Time pressure must not compromise the securing of evidence. A structured approach ensures that important information is retained and can be evaluated at a later date.
  • The Cyber Kill Chain and MITRE ATT&CK® framework help incident response teams, to systematically classify attacks, better understand attacker tactics and techniques, and specifically develop one's own detection mechanisms.

Forensics in Incident Response: Expert Interview with Thomas Ringhof, Digital Forensic Investigator at r-tec (part of the accompio group)

How does a forensic analysis proceed after a cyberattack? Which data is particularly important? And how can concrete improvements be derived from an incident? Thomas Ringhof answers all these questions in the full video interview.

What is digital forensics?

Digital forensics refers to the systematic examination of digital traces following a security incident. Forensic investigators secure log files, memory dumps, network data and other artifacts to reconstruct the sequence of an attack without gaps.

Unlike a classic vulnerability scan, digital forensics examines an incident that has already occurred: how did the attacker get in, which systems did they compromise, and what data was affected?

Digital forensics thus provides the robust factual basis for any further decision in Incident Response, from containment to reporting to authorities or insurers.

Forensics begins where speculation ends

Following a security incident, the initial focus is on containing the attack. However, just as important is the question of how the incident could have happened in the first place.

This is precisely where digital forensics comes in. It reconstructs the sequence of an attack, identifies the entry point, and makes it understandable which systems were affected and what activities the attacker carried out.

This provides the basis for informed decisions, both during incident response and for the long-term improvement of security strategy.

Secure evidence, before it's lost.

Every cyber attack leaves digital traces. These include log files, memory dumps, network data, and artefacts on end devices, among others.

The sooner responsible parties secure this information, the more completely the attack progression can be reconstructed. At the same time, clean evidence preservation is crucial in order not to inadvertently alter data or lose important clues.

A structured data backup is therefore one of the most important tasks in the first hours of an incident.

To systematically reconstruct the attack sequence

A single log file rarely answers all questions. Only by combining different data sources does it become possible to trace the entire attack path, from initial access through lateral movement to persistence mechanisms or potential data exfiltration. .

Methodologies and frameworks such as the Cyber Kill Chain or that MITRE ATT&CK® Framework aid in contextualising individual activities within an overall picture and recognising typical attack patterns.

From analysis to concrete measures

The insights gained from digital forensics are directly incorporated into technical and organisational improvements. These include, for example, the adaptation of detection rules, the hardening of affected systems, improvements in identity and access management, or optimisations to existing incident response processes.

The goal is to manage the current incident and to detect or prevent similar attacks in the future at an early stage.

„An incident is only truly concluded when we can retrace the attacker's steps – anything else remains speculation.“

— Thomas Ringhof, Digital Forensic Specialist at r-tec (part of the accompio group)

The greatest challenges in practice

In many incident response operations, precisely the information needed for a complete analysis is missing.

Unactivated logging, retention periods that are too short, or incomplete data significantly hinder reconstruction. At the same time, incident response teams must work under severe time pressure, balancing rapid response with careful analysis.

Good preparation therefore often determines how successful a subsequent forensic investigation will be.

What role do AI and automation play?

Automation and artificial intelligence are increasingly supporting forensic analysis in the evaluation of large datasets and the identification of conspicuous patterns.

However, the actual assessment of an attack will continue to be the task of experienced experts. Complex attack scenarios in particular require contextual knowledge, experience, and the ability to translate technical findings into concrete recommendations for action.

Transparent castle on a digital server, symbolising IT security solutions.

Digital forensics brings clarity after a cyber attack

accompio analyses the attack patterns and vulnerabilities in your IT infrastructure so that an incident does not reoccur.

Conclusion: Those who understand the attack will prevent it permanently

Incident response doesn't end with the restoration of business operations. Only when companies understand how an attacker operated, which vulnerabilities they exploited, and what traces the attack left behind, can effective protective measures be derived.

Digital forensics provides exactly this understanding, thereby creating the foundation for a more resilient security strategy.

Mann talks about IT services at Accompio, IT solutions for companies.

About the author

Thomas Ringhof is an Incident Responder and Digital Forensic Examiner at r-tec (part of the accompio group) and supports companies with the forensic investigation of security incidents.

FAQ: Frequently Asked Questions on Digital Forensics in Incident Response

What is digital forensics in incident response?

Digital forensics is the systematic analysis of a cyber attack. The goal is to secure digital evidence, reconstruct the attack sequence, and gain reliable insights into the attacker's cause, impact, and methods. It is an essential component of professional incident response.

Der Unterschied zwischen Incident Response und digitaler Forensik liegt in ihrem Umfang, ihren Methoden und ihren Zielen. **Incident Response (IR)** ist ein proaktiver und reaktiver Prozess zur Bewältigung von Sicherheitsvorfällen. Sein Hauptziel ist es, die Auswirkungen eines Vorfalls zu minimieren, die normale Geschäftstätigkeit wiederherzustellen und zukünftige Vorfälle zu verhindern. **Merkmale von Incident Response:** * **Umfang:** Breiter und umfassender. Es beginnt mit der Erkennung und Analyse eines Vorfalls und geht weiter zu Eindämmung, Beseitigung und Wiederherstellung. Es umfasst auch Wiederaufbaumaßnahmen und Lernen aus dem Vorfall. * **Ziele:** * Schnelle Erkennung und Reaktion auf Sicherheitsvorfälle. * Begrenzung des Schadens und der Auswirkungen eines Vorfalls. * Wiederherstellung des normalen Betriebs so schnell wie möglich. * Verhinderung ähnlicher Vorfälle in der Zukunft. * **Methoden:** * Entwicklung und Umsetzung von Incident-Response-Plänen. * Einrichtung von Teams zur Reaktion auf Vorfälle (CSIRTs/SOCs). * Verwendung von Sicherheitsüberwachungswerkzeugen, Alarmen und Protokollen. * Kommunikation und Koordination mit verschiedenen Interessengruppen. * Erkundung und Wiederherstellung von Systemen. * **Zeitrahmen:** Konzentriert sich auf die unmittelbaren und kurzfristigen Maßnahmen während und direkt nach einem Vorfall. **Digitale Forensik** ist ein Teilbereich von Incident Response, der sich spezifisch mit der Untersuchung von digitalen Beweismitteln befasst. Ihr Hauptziel ist die Sammlung, Erhaltung, Analyse und Berichterstattung über digitale Daten auf eine Weise, die vor Gericht, in internen Untersuchungen oder für andere rechtliche Zwecke zulässig ist. **Merkmale der Digitalen Forensik:** * **Umfang:** Enger und spezifischer. Es konzentriert sich auf die technische Untersuchung von digitalen Geräten und Daten. * **Ziele:** * Aufdeckung der Ursache und des Umfangs eines Vorfalls. * Identifizierung von Angreifern oder den am Vorfall Beteiligten. * Sammeln von Beweismitteln zur Unterstützung von Strafverfolgungs- oder internen Maßnahmen. * Dokumentation von Aktionen und Aktivitäten, die während des Vorfalls stattgefunden haben. * **Methoden:** * Sichere Sammlung und Erhaltung digitaler Beweismittel (z. B. Festplattenkopien, Spezialsicherung, RAM-Dumps). * Analyse von Betriebssystem-Artefakten, Anwendungsdaten, Netzwerkverkehr und mehr. * Verwendung spezialisierter forensischer Werkzeuge und Techniken. * Erstellung detaillierter Berichte über die gefundenen Beweismittel und Schlussfolgerungen. * **Zeitrahmen:** Kann sowohl während als auch nach einem Vorfall durchgeführt werden, oft mit einem Fokus auf die Rekonstruktion vergangener Ereignisse. **Zusammenfassend lässt sich sagen:** * **Incident Response** ist der **Gesamtprozess** (das "Was" und "Warum" der Reaktion auf einen Vorfall), um einen Vorfall zu bewältigen und den Betrieb wiederherzustellen. * **Digitale Forensik** ist eine **spezifische disziplinäre Aktivität** innerhalb eines IR-Prozesses (das "Wie" der Beweismittelsammlung und -analyse), um die technischen Details eines Vorfalls zu verstehen und Beweismittel zu sichern. Man könnte sagen, dass digitale Forensik ein entscheidendes Werkzeug im Werkzeugkasten des Incident Response ist, aber nicht der gesamte Werkzeugkasten. Ein effektiver Incident Response benötigt sowohl eine robuste Strategie für die Reaktion auf Vorfälle als auch die Fähigkeit zur Durchführung digitaler forensischer Untersuchungen, wenn nötig.

Incident response encompasses all measures to detect, contain, and remediate a security incident. Digital forensics focuses on securing evidence, technically analysing the attack, and fully reconstructing the sequence of events. Both disciplines are complementary and closely linked.

Following a cyber attack, the following data should be backed up: * **Critical System Data:** This includes operating system files, configuration settings, and essential application data that are necessary for your systems to function. * **User Data:** This refers to all personal files, documents, emails, and other data belonging to your users. * **Application Data:** Any data specific to the applications used within your organisation, such as databases, customer records, financial information, and intellectual property. * **Logs and Audit Trails:** These are crucial for forensic analysis to understand how the attack occurred, what data was compromised, and to identify vulnerabilities. This includes system logs, security logs, application logs, and network traffic logs. * **Configuration Files:** These contain the settings for your operating systems, applications, and network devices, which are vital for restoring functionality. * **Intellectual Property and Sensitive Information:** Any proprietary data, trade secrets, or confidential information that is of high value to the organisation. * **Communication Records:** Relevant emails, chat logs, or other communication data that might be important as evidence or for understanding the scope of the attack. The aim is to secure enough data to enable a full recovery of systems and operations, and to conduct a thorough investigation into the incident.

Log files, memory dumps, network data, endpoint information, authentication logs, and artefacts on affected systems are particularly important. The more complete this data is, the better the attack can be reconstructed.

Why is prompt evidence preservation so important?

Many digital traces change quickly or are lost due to restarts, system changes, or cleaning measures. Early backup of relevant data increases the likelihood of fully reconstructing the attack path.

How is a cyber-attack forensically analysed?

The analysis begins with securing relevant data sources. Subsequently, forensic investigators chronologically order events, identify attack techniques, and reconstruct the entire attack path. Frameworks such as the Cyber Kill Chain or that MITRE ATT&CK® Framework assist in systematically classifying the observed activities.

Ein Memory Dump ist eine Exaktkopie des gesamten Inhalts des Arbeitsspeichers (RAM) eines Computers zu einem bestimmten Zeitpunkt. Er wird erstellt, wenn ein System abstürzt oder sich nicht mehr reagiert. Ein Memory Dump ist wichtig, weil er Entwicklern und Technikern dabei helfen kann, die Ursache eines Absturzes oder Problems zu ermitteln. Durch die Analyse des Dumps können sie Informationen darüber gewinnen, was das System zum Absturz gebracht hat, und dann Korrekturen entwickeln, um das Problem zu beheben. Memory Dumps sind auch bei der forensischen Analyse nützlich. Sie können verwendet werden, um Beweise für Cyberkriminalität oder andere böswillige Aktivitäten zu sammeln.

A memory dump is a snapshot of a system's RAM. It often contains clues about running processes, malware, network connections, or encryption keys, and frequently provides information that is no longer present in log files.

How to tell if attackers are still in the network

Forensic analysts examine, among other things, active processes, network connections, persistence mechanisms, user accounts, and unusual activities. The aim is to determine whether the attacker still has access to systems or if the team has already removed them completely.

What role does the MITRE ATT&CK® Framework play?

MITRE ATT&CK describes known attack techniques and tactics in a structured model. Incident response and forensics teams use the framework to systematically classify attacks, improve detection rules, and strategically develop security measures.

Kann künstliche Intelligenz die digitale Forensik ersetzen?

No. AI analyses large amounts of data, identifies anomalies, and supports experts in their evaluation. However, the assessment of complex attack scenarios and the derivation of suitable measures still require the experience of specialised incident response and forensics experts.

How can companies prepare for a forensic contingency?

Companies should ensure comprehensive logging, retain log data for a sufficient period, define incident response processes, assign responsibilities, and conduct regular drills or attack simulations. Good preparation significantly improves the quality of forensic analyses and reduces response times in the event of an incident.

Woman with a headset in customer service at Accompio IT Services.

Get in touch with us

We at accompio will be happy to help you.

Arrange an initial consultation

This field is for validation purposes and should be left unchanged.
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form

From time to time we would like to inform you about our products and services as well as other content that may be of interest to you. You can unsubscribe from these communications at any time. If you agree to us contacting you for this purpose, please tick the following box. You can revoke your consent at any time with effect for the future - via the unsubscribe link at the end of each e-mail or by e-mail to info@accompio.com.

We process and store your data. You can find further information at Privacy Policy.

})