SKIP TO CONTENT
SERVICE LINE / SERVER FORENSICSS-02

Server Forensics Expert Witness Services

Forensic examination of the systems that sit behind the endpoint — domain controllers, file and application servers, hypervisors, web servers, and databases — reconciled with identity and network records into one timeline that states who authenticated, what they reached, and what moved.

SYSTEMS
Bare-metal · VM · Hypervisor
IDENTITY
Active Directory · Entra ID · LDAP
DATA
SQL Server · Oracle · MySQL · Postgres
ACQUISITION
Live, order of volatility · Snapshot
DELIVERABLE
FRCP 26(a)(2)(B) report
ROLES
Testifying · Consulting · Neutral
IN SHORT

Server forensics is the examination of servers and the enterprise records they generate — authentication, file access, database, and network logs — to establish how an account obtained access, where it moved, what data it reached, and what left the environment. It is the discipline that answers scope questions an endpoint examination cannot.

What a server examination covers

One server rarely holds the answer. The work is correlation: reconciling identity records, host artifacts, application logs, and network telemetry that each hold one fragment of the same event.

Identity and authentication

Most enterprise disputes begin at the directory. Domain controller security logs record interactive, network, and remote-desktop logons, failures and their reason codes, explicit-credential use, and the assignment of privileged rights at logon. Kerberos ticket requests show which service a principal asked for and from where, which is how service-account abuse and pass-the-ticket activity become visible. Group membership changes, new accounts, password resets, and delegation changes are recorded in the same stream and are frequently the clearest marker of privilege escalation.

File, application, and database systems

  • File servers — object-access auditing records share connections and per-file handle requests naming the account, the client address, and the access mask requested. Where auditing was not enabled, the file system artifacts on the server itself still carry timestamps, the change journal, and shortcut and index records.
  • Web and application servers — request logs give method, path, status, response size, referrer, and user agent per request, which supports both intrusion analysis and volume-transferred questions. Application logs, error logs, and configuration history sit alongside them.
  • Databases — native audit trails where enabled, and otherwise the transaction log, redo log, or binary log, which record data modification even when auditing does not. Query and connection history, linked-server and export jobs, and scheduled tasks that write to disk or to a remote endpoint are common evidence of bulk extraction.
  • Hypervisors and virtual infrastructure — management logs recording creation, cloning, reversion, and deletion of virtual machines and snapshots; datastore contents; and the snapshot chain itself, which can preserve a state the live system no longer has.
  • Backups and archives — job catalogues, restore history, and retention configuration, which answer both what existed on a given date and whether anything interfered with its retention.

Network and egress

Firewall, proxy, VPN, DNS, and NetFlow records establish the outside edge of the picture: which external destinations were reached, when, over what protocol, and how many bytes moved in each direction. These are the records that convert “a user had access” into a defensible statement about what actually left the environment, and they are usually retained on shorter schedules than anything else — which is why they are preserved first.

Where this comes up

  • Intrusion and ransomware matters, where scope, dwell time, and the fact and extent of data theft drive both notification obligations and damages
  • Insider and departing-employee matters, where the endpoint shows intent and the servers show reach
  • Trade-secret and data-misuse claims, where the dispute is what a defendant could access versus what they demonstrably took
  • Spoliation and preservation disputes, where log retention settings, snapshot deletion, and backup expiry are themselves the evidence
  • Rebuttal engagements testing another expert's reconstruction against the same log set

The forensic methodology for reconstructing an intrusion end to end is set out in more detail in Reconstructing a Ransomware Incident.

How the engagement runs

  1. Conflicts and scope. Parties run for conflicts, then a scoping call to establish the question, the systems in play, the deadline, and the role — testifying, consulting, or neutral.
  2. Preservation instructions. Issued the same day where a matter is live: extend log retention, suspend snapshot consolidation and backup expiry, preserve the current state of affected systems, and stop remediation that would destroy the record before it is captured.
  3. Collection. Executed in order of volatility and recorded as it happens — memory and running state, then logs and configuration, then images or snapshots. Every export is hashed on receipt, and the account, command, and timestamp behind each collection is logged.
  4. Normalisation and correlation. Timestamps are reconciled to a single reference and time zone, clock sources and drift are recorded, and events from identity, host, application, and network sources are aligned into one timeline.
  5. Analysis and findings. The timeline is tested against the question, alternative explanations are considered on the record, and each finding is tied to the log line or artifact it rests on.
  6. Report and testimony. Written opinion with exhibits, then deposition and trial where the matter reaches them.
EVIDENCE SOURCEWHAT IT ESTABLISHESUSUAL CONSTRAINT
Domain controller security logsWhich account authenticated where, when, and with what rightsVolume-driven rollover; audit policy may never have recorded it
File server object-access auditingPer-file access by account and client addressFrequently disabled by default in the enterprise
Database transaction / redo / binary logsData modification, and often the content of the changeRetention tied to backup cycle; truncated on log backup
Proxy, firewall, NetFlowExternal destinations reached and bytes transferredShortest retention of any source; frequently 30 days or less
Hypervisor management logsCreation, cloning, reversion, and deletion of machines and snapshotsOverwritten by routine operations; separate from guest logs
Backup cataloguesWhat existed on a given date, and whether retention was alteredRestore capacity and time, not availability, is the limit
Retention is why preservation is the first step rather than a later one. The most probative sources are commonly the ones with the shortest default retention.

What you receive

The deliverable for a retained testifying expert in federal court is a report meeting Fed. R. Civ. P. 26(a)(2)(B) — a complete statement of the opinions and their basis, the facts or data considered, the exhibits relied on, qualifications and a ten-year publication list, a four-year testimony list, and a statement of compensation. In a server matter the exhibits are usually the timeline, the correlated log extracts behind each entry, and a statement of what each source does and does not record.

Where the vehicle is a motion rather than a trial, the same analysis is delivered as a declaration under 28 U.S.C. § 1746 or a state-law affidavit — the common posture on preservation, spoliation, and motions to compel. Rebuttal reports responding to another expert’s reconstruction are due within 30 days of that disclosure unless the court orders otherwise. See the expert witness testimony page for how disclosure, deposition, and Rule 702 practice fit together.

What server evidence can and cannot establish

  • A log records what it was configured to record. Absence of an event is evidence that the event was not logged, which is a different proposition from the event not happening. Whether the difference matters is testable by examining the audit configuration in force at the time.
  • Volume is not the same as content. Network records establish that a quantity of data moved to a destination. Establishing what that data was requires the staged copy, the source records, or the destination itself.
  • An account is not a person, and a host is not a user. Attribution across a domain requires corroboration, and shared service accounts, jump hosts, and remote-access tooling all break the chain from session to human being.
  • Clocks disagree, and the disagreement is evidence. Time-zone normalisation and clock-drift measurement are part of the analysis, not a preliminary — an uncorrected offset between two sources produces a sequence of events that never happened.

Questions counsel ask

Can a server be examined without taking it offline?

In most cases, yes. Production systems are rarely surrendered, so the usual approach is live acquisition in order of volatility — memory first, then network state and running processes, then targeted collection of logs and file system artifacts — followed by a snapshot or image where the platform allows it. A virtual machine can often be snapshotted with no downtime at all. The trade-off is that a live acquisition cannot be hash-verified against an unchanged source, so the acquisition method and its consequences are documented in the report rather than glossed over.

Our logs only go back thirty days. Is the investigation over?

Rarely. Log retention is a starting inventory, not the whole record. Backups and archive tiers often hold older copies; endpoint and EDR telemetry, firewall and proxy records, mail gateway logs, and identity provider sign-in data are frequently retained on different schedules; and file system and registry artifacts on the server itself are not governed by log retention at all. What retention does control is urgency, which is why preservation — extending retention and capturing snapshots — is the first action in a live matter rather than a later one.

Can you tell how much data was taken?

Sometimes precisely, more often as a bounded range. Proxy and firewall records give bytes transferred per session; NetFlow gives volume per flow; web server logs give the size of each response; and on Windows the system resource usage monitor records bytes sent per application. Where an archive was staged before transfer, its size and contents may still be recoverable. What these sources give is volume and destination, not necessarily contents, so an honest answer distinguishes what was demonstrably transferred from what was accessible and cannot be excluded.

How do you handle virtual servers and snapshots?

A virtual machine is easier to preserve than a physical one, because the disk is already a file. The virtual disk and its snapshot chain are copied and hashed, memory state is captured where the hypervisor retains it, and the hypervisor's own management logs are collected alongside — those record who created, cloned, reverted, or deleted a machine, which is frequently the evidence that matters in a spoliation dispute. Reverting or consolidating a snapshot chain before it is preserved destroys evidence, so that instruction goes out at the first call.

Will you need administrator credentials to our environment?

Often the cleanest route is that the client's own administrators execute defined collection steps under the examiner's written direction and supervision, which avoids handing out privileged access and keeps the client in control of production systems. Where the examiner does collect directly, access is scoped to the collection account, the account and its actions are recorded, and every command run is logged as part of the acquisition record. Either arrangement is documented so the collection can be reproduced and challenged.

Can this be done under a protective order without disrupting operations?

Yes, and it is the normal posture. Collection is scheduled around maintenance windows, scoped to the custodians, systems, and date ranges the ESI protocol defines, and performed on copies so that analysis never touches production. Where the data is competitively sensitive, review can be confined to a designated environment and an attorneys'-eyes-only tier under the protective order already entered in the case.
ENGAGE A SERVER FORENSICS EXAMINER

Enterprise logs expire on a schedule that has nothing to do with your discovery deadline. Send the matter, the venue, the key dates, and a description of the environment — a conflicts check and a scoping call follow.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

Attorney advertising / expert services. This page describes forensic practice and the procedural rules that govern expert evidence in general terms. It is not legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum. Prior results do not guarantee a similar outcome.