Method

How we work.

Forensic work is usually read by someone who was not there.

That reader cannot ask what the console showed, why a step came before another, or which detail was already gone when the work began. They can only read what was recorded.

So the method is arranged around one test: can a competent reviewer follow the path from evidence to conclusion later, without us in the room to explain it? Every step below exists to leave that path intact.

What a later reviewer needs

  • The question the work was meant to answer
  • The authority the work was performed under
  • What evidence existed, and what did not
  • How state was captured, and when
  • Which statements are observed and which are derived
  • What the evidence cannot support
Baseline

A measured difference is stronger than a stated one.

Where change is planned, we record the relevant state before it happens.

A remediation, a deployment, a hardware replacement or an authorized test all share a problem: once the change lands, the condition it replaced is gone.

With a baseline in hand, an outcome becomes a comparison between two recorded states — what was there, and what is there now. Recorded first, a baseline is evidence. Assembled afterwards from memory, it is recollection.

  • Recorded pre-state
  • Authorized change
  • Recorded post-state
  • Measured difference

A baseline cannot be taken late

Where no pre-state was captured before the change, we say so, and the finding carries that limitation with it. We do not reconstruct a baseline that was never recorded.

The workflow

Nine steps, in order, each one leaving a record.

Scope, available evidence and known limitations are settled before conclusions are written. The order is part of the method, not a summary of it.

  1. Understand the question

    Work begins with what actually needs to be established, and for whom. An incident review, a dispute, a compliance question and an internal post-mortem can involve the same system and require different evidence.

    Naming the question first keeps collection bounded and keeps the findings answerable.

  2. Confirm authorization and scope

    Systems, accounts, data and time ranges are agreed in writing before work begins. The scope states what is included, what is excluded, and what must be protected.

    It does not expand quietly. A change of scope is a decision a person makes, approves and records before the work follows it.

  3. Identify what evidence exists

    We establish what is genuinely available: which logs survive and how far back, which devices remain, what has already rotated, been overwritten or been replaced.

    Absence is part of the answer. Knowing that something does not exist keeps a gap from being read as a result.

  4. Preserve relevant state

    Where it still exists, bounded pre-state and post-state are captured while they are still current, with acquisition conditions and chronology recorded alongside them.

    Preservation stays inside the authorized scope. More collection is not automatically better evidence, and never substitutes for capturing the right state early.

  5. Examine and correlate

    Artifacts are examined in relation to each other and to the state around them. A log entry, a configuration, a packet capture and a disk artifact each answer part of a question.

    The useful signal is usually in how they agree, how they conflict, and what the surrounding state was doing at the same moment.

  6. Distinguish fact from inference

    The record separates what was observed from what was derived from it, and both from what remains uncertain. Where more than one explanation fits the evidence, the alternatives are named rather than resolved by preference.

    Where a weaker statement is true and a stronger one is not yet supported, we write the weaker one.

  7. Document limitations

    Gaps, assumptions, tool constraints and the conditions of acquisition are written into the record instead of left out of it.

    We state what the evidence cannot support as plainly as what it can. A limitation disclosed by the examiner is a fact; one discovered later by a reviewer is a problem.

  8. Prepare reviewable findings

    Findings are assembled so another competent reviewer can follow the same path later: chronology, provenance, method, what was compared, and the open questions that remain.

    Reviewability well beyond the immediate response window is a design goal, not a guarantee. It depends on the available source evidence and the chosen retention scope, and nothing in this step recreates evidence that was never captured.

  9. Close with human review

    A person reads the record, tests the reasoning against the evidence, and reaches the conclusion. That person owns it.

    No finding is released because a process produced it. Where the reasoning does not hold, the work returns to an earlier step rather than forward to a conclusion.

Human authority

Software prepares the record. A person decides what it means.

Software and AI are useful here for work that is mechanical, repetitive and easy to get wrong at scale: organizing authorized evidence, comparing captured states, tracing relationships between artifacts, surfacing discrepancies, and assembling packages for review.

That is preparation. It is not judgment. A comparison can show that two states differ; it cannot say whether the difference matters or whether it was authorized.

Nothing approves itself.

Scope changes, evidence promotion, consequential conclusions and the release of findings are human-gated. Automation may prepare and propose. A person decides, and remains accountable for the decision.

What automation may do

  • Organize and index authorized evidence
  • Compare captured states and surface differences
  • Trace relationships between artifacts
  • Flag discrepancies and expected data that is missing
  • Assemble preservation and review packages

What it may not do

  • Reach a consequential conclusion on its own
  • Approve its own scope or its own output
  • Collect beyond what was authorized
  • Decide that a matter is finished
Boundaries

The record concerns the work and the system, not the monitoring of people.

Lineage without surveillance is a boundary on what we collect, not a description of our intentions.

What we record

  • System state before and after a scoped event
  • The artifacts examined, and where they came from
  • Who authorized the work, and when
  • The steps taken, in order, with their timing
  • The limits of the evidence and the questions left open

What we do not record

  • Continuous monitoring of individuals
  • Behavior, productivity, or person scoring
  • Always-on capture outside a scoped event
  • Anything beyond the authorized systems and time range

People appear in a forensic record where an authorized action requires an actor — an account that made a change, an approval that was given. That is attribution inside a declared scope. It is not observation of a person.

The question comes first. What the evidence can carry is settled early, not assumed.

Scope and authorization are agreed before work begins, and an inquiry does not guarantee acceptance. Please do not send credentials or sensitive evidence with a first message.