Forensics and Evidence Handling in Industrial Environments
OT forensics differs from IT forensics in ways that catch even experienced IT incident responders off guard: many field devices have no persistent storage to image, limited or no logging capability, and physically disconnecting a device to preserve evidence can itself have safety or availability consequences that a typical IT forensic playbook never has to consider.
A practical OT forensics approach prioritizes evidence sources that can be collected without disrupting the process: network capture from passive taps (already discussed as a core telemetry source), historian data showing process behavior before, during, and after the event, engineering workstation and jump host logs, and physical access logs for the facility or cabinet in question. Where a controller itself must be examined, this should happen through a coordinated, engineering-approved process -- often during a planned outage -- rather than an improvised live forensic action that risks destabilizing the process.
Chain of custody matters just as much in OT as IT, and arguably more, given the likelihood of regulatory involvement after a significant critical infrastructure incident: every piece of evidence -- network captures, historian exports, configuration snapshots, physical access records -- should be logged with who collected it, when, how, and how its integrity was preserved, because that evidence may later need to withstand scrutiny from a regulator, insurer, or legal proceeding.
Finally, OT forensic investigations benefit enormously from having a known-good configuration baseline captured before an incident ever happens -- comparing a suspect system's current state against a trusted prior baseline is often far faster and more reliable than attempting to reconstruct 'normal' from scratch during an active investigation.
Reading
6 minutes