Forensic tooling can change the thing examined
The act of investigating leaves traces, which means some of what you find later is your own footprints.
Tools write files, create registry entries, open network connections and update access times. An analyst who cannot distinguish their own activity from the attacker's will eventually chase themselves. Recording exactly what was run and when is what makes the timeline interpretable afterwards.
More on Digital forensics
- Forensic copies protect original evidenceMark the copy, never the original
- Hashes can show evidence stayed unchangedThe same short string, twice
- Timestamps need interpretationOne moment, three different times
- Memory can reveal what disk cannotIt has to unwrap itself to run
- Deleted does not always mean goneThe card, not the book
- Cloud forensics depends on provider evidenceYou get what comes through the hatch
