Network evidence
Fictional DNS, proxy, firewall, flow, routing, connection, gateway, service, or packet-summary records relevant to an approved case question.
Learn how an authorized defender correlates supplied fictional network, identity, application, file, process, storage, cloud, deployment, support, business, and source-health evidence while preserving original timestamps, normalizing time carefully, resolving conflicts, tracking source independence, and versioning every major timeline change.
Lesson Progress
High School Intermediate • I12: Digital Forensics Basics • Lesson 6 of 8
Readiness Check
0/5 ready
Professional Hook
The fictional Northbridge case contains file timestamps in local time, identity records in UTC, network flows in local time, minute-level support reports, a process snapshot at one exact moment, and application events that arrived twelve minutes late. Without careful normalization, the copy operation appears to occur after the duplicate files already exist. Once event time and receipt time are separated, the sources support a consistent automated workflow.
Weak correlation
Sort every exported timestamp, count every dashboard as independent confirmation, delete conflicts, and present one exact sequence without source-health or precision limits.
Professional correlation
Preserve original values, understand source behavior, normalize with documented methods, map source independence, use ranges where needed, retain conflicts, and version the timeline.
Objective 1
Explain how fictional network, DNS, proxy, firewall, flow, application, identity, storage, cloud, support, and business records contribute different pieces of a forensic timeline.
Objective 2
Normalize fictional timestamps by preserving original values, source time zones, clock state, delay, resolution, collection time, and conversion method.
Objective 3
Distinguish genuinely independent evidence from dashboards, screenshots, exports, and summaries derived from the same underlying source.
Objective 4
Resolve fictional conflicts by documenting source health, missing records, alternative explanations, confidence, and the reason for every timeline revision.
Objective 5
Create a defensible fictional network-and-cloud correlation package with source maps, normalized events, findings, limitations, version history, and portfolio-safe reporting.
Why This Matters
Fictional sources record different stages of the same event. A file system may record object creation, an application may record job completion, a network device may record a connection start, a cloud platform may record an object operation, and a collector may record when the event arrived. The analyst must preserve these meanings and avoid converting several different times into one unsupported certainty.
Core Concept
Preserve
Keep every fictional original timestamp, source field, time zone, offset, resolution, clock state, receipt time, and source-health condition.
Normalize
Convert to a common reference only with a documented method, uncertainty range, drift or delay note, and parent evidence.
Correlate
Compare genuinely independent fictional file, process, identity, application, network, cloud, deployment, support, business, and source-health evidence.
Version
Preserve every fictional timeline revision, new source, correction, conflict, reviewer decision, affected finding, and confidence change.
Key Vocabulary
Fictional DNS, proxy, firewall, flow, routing, connection, gateway, service, or packet-summary records relevant to an approved case question.
Fictional platform records describing identity, administrative, storage, sharing, configuration, service, API, or object activity within a hosted environment.
The fictional process of comparing events from several sources to understand order, relationship, agreement, conflict, and uncertainty.
The fictional time exactly as recorded by its source before normalization or interpretation.
A fictional converted time placed into a common reference zone while preserving the original value and conversion method.
A fictional difference between a source clock and the trusted reference time.
A fictional gap between when an event occurred and when the record became available to the collector or analyst.
The level of fictional time precision supported by a source, such as minutes, seconds, or milliseconds.
The fictional relationship connecting a normalized timeline event to every original evidence record and transformation used to create it.
Support from a genuinely different fictional source with its own collection path, event-generation logic, and limitations.
A fictional numbered state of the timeline that preserves changes, new evidence, conflicts, corrections, reviewer decisions, and prior conclusions.
A fictional entry documenting when sources disagree about time, actor, action, result, scope, or sequence.
The fictional absence of an expected event, used cautiously only when source health, coverage, retention, ownership, and event-generation conditions are verified.
A fictional explanation of how strongly the timeline relationship is supported and which limitations or alternatives remain.
Evidence Sources
Examples
Fictional query time, requested name, response, resolver, client, cache state, result code, and source health.
Can support
That a fictional system attempted to resolve a service or destination name within the source's coverage.
Cannot prove alone
That a connection succeeded, content transferred, a human initiated the request, or every resolution attempt was retained.
Correlate with
Proxy, firewall, flow, process, application, identity, and cloud records.
Examples
Fictional source identity, destination category, request method, result, bytes, policy action, session, and timestamp.
Can support
That a fictional request passed through the gateway and received a recorded policy or service result.
Cannot prove alone
The full content, human intent, complete session behavior, or activity that bypassed the gateway.
Correlate with
DNS, endpoint process, identity, application, firewall, cloud, and vendor records.
Examples
Fictional source and destination, ports, protocol, direction, action, byte counts, duration, session identifiers, and device time.
Can support
That a fictional network relationship was allowed, denied, or observed under the recorded conditions.
Cannot prove alone
Application meaning, payload content, successful authentication, user intent, or exact business impact.
Correlate with
Process connections, DNS, proxy, application, identity, cloud, and service records.
Examples
Fictional request identifier, job, route, object, response, user or service identity, retry, error, and processing time.
Can support
How a fictional workflow processed a request and which service action produced an observed result.
Cannot prove alone
Complete platform activity when logging is delayed, sampled, filtered, unhealthy, or missing expected event types.
Correlate with
Identity, process, file, storage, cloud, network, deployment, support, and business records.
Examples
Fictional sign-in, token, session, role, service identity, device context, authentication result, and lifecycle event.
Can support
Which fictional identity context was active and how it relates to an approved workflow.
Cannot prove alone
Which human controlled a shared or service identity, every later action, or intent.
Correlate with
Application requests, process ownership, cloud audit, storage transactions, network connections, and role records.
Examples
Fictional object read, write, copy, delete, version, share, public-link, permission, download, and administrative events.
Can support
Which fictional platform action was recorded for an object or access setting within verified coverage.
Cannot prove alone
That no unrecorded activity occurred outside retention, event coverage, time, account, region, or platform boundaries.
Correlate with
Identity, application, network, process, file metadata, support, and vendor records.
Examples
Fictional version, artifact, configuration, rollout, approval, runtime state, startup time, rollback, and environment.
Can support
Which approved or outdated fictional version and configuration should have been active during an event.
Cannot prove alone
That repository state exactly matched runtime state without startup, process, integrity, and deployment validation.
Correlate with
Process, application, file, cloud, monitoring, support, and recovery records.
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Examples
Can support
Cannot prove alone
Correlate with
Timestamp Normalization
Is the fictional value an event, receipt, processing, export, collection, file, or report time?
Strong method
Preserve the original field name, source, meaning, and value before converting it.
Analysis risk
Combining different timestamp meanings into one generic time column.
Which zone and offset apply, and was the fictional source clock synchronized or drifting?
Strong method
Record the original zone, normalized zone, daylight-saving state, drift, reference, and conversion method.
Analysis risk
Assuming every source uses the same clock or silently correcting a value.
Did queueing, forwarding, export, parsing, outage, or batching delay the fictional record?
Strong method
Preserve both event and receipt times and document the delay as a source-health limitation.
Analysis risk
Ordering events by when the analyst received them.
Does the fictional source support minutes, seconds, milliseconds, a batch, or only an estimated range?
Strong method
Use a range or grouped ordering when exact sequence is unsupported.
Analysis risk
Inventing exact order from coarse timestamps.
Are the fictional records genuinely independent or several views of the same underlying evidence?
Strong method
Trace dashboards, screenshots, exports, and summaries to their parent source and common failure modes.
Analysis risk
Counting duplicate views as separate confirmation.
Did delayed evidence, corrected timing, owner clarification, or reviewer feedback change the fictional timeline?
Strong method
Keep the prior version and record the reason, author, reviewer, affected events, findings, and confidence.
Analysis risk
Silently replacing the earlier timeline.
Correlation Fields
Purpose
Creates a unique fictional reference for the normalized event and its revision history.
Fictional example
NRA-T-014-v2.
Quality standard
Unique, never reused, and linked to parent evidence.
Purpose
Preserves the fictional source value while placing the event into a common reference zone.
Fictional example
09:17 UTC-04:00 preserved beside 13:17 UTC.
Quality standard
Includes source field, zone, offset, resolution, and conversion method.
Purpose
Records fictional delay, completeness, retention, parsing, clock state, ownership, and expected coverage.
Fictional example
Application records arrived twelve minutes late and were later validated.
Quality standard
Evaluated for the relevant event window.
Purpose
States exactly what the fictional source records without adding interpretation.
Fictional example
The copy worker targeted approved-copy for job 441.
Quality standard
Uses exact fields and evidence identifiers.
Purpose
Connects fictional process, file, identity, application, network, cloud, deployment, and business events.
Fictional example
P-03, A-03, APP-17, ID-07, NET-11, and CLOUD-21.
Quality standard
Independent and duplicate-source relationships remain visible.
Purpose
Preserves disagreement, missing evidence, alternate mechanisms, or unresolved ordering.
Fictional example
File creation appears before application delivery because the application source was delayed.
Quality standard
The conflict remains documented even after a preferred explanation is selected.
Purpose
Explains how strongly the fictional relationship is supported and what remains uncertain.
Fictional example
High confidence in the automated copy mechanism; low confidence in exact human awareness time.
Quality standard
Tied to source quality, alternatives, and evidence gaps.
Purpose
Records the fictional author, reviewer, reason, changed sources, affected findings, and confidence updates.
Fictional example
Version 2 added delayed application records and adjusted three events.
Quality standard
Earlier versions remain preserved and reviewable.
Defensive Workflow
Restate the fictional question, approved sources, owners, time window, privacy limits, and evidence identifiers.
Output: Correlation objective and approved source map.
Confirm fictional integrity, lineage, collection method, zone, clock state, delay, retention, parsing, and completeness.
Output: Source-health and normalization register.
Record fictional identifiers, original timestamps, actors, objects, actions, results, sessions, destinations, and source references.
Output: Original event table.
Convert events to a common zone while preserving original values, drift, delay, resolution, uncertainty, and method.
Output: Normalized event table with ranges.
Identify independent sources, duplicate views, shared collectors, transformations, and common failure modes.
Output: Source-dependency map.
Compare fictional process, file, identity, application, network, cloud, deployment, support, and business records.
Output: Correlation matrix and conflict register.
Order events only as precisely as supported, retain uncertain ranges, link parent evidence, and record every revision.
Output: Versioned normalized timeline.
Separate observations, supported relationships, alternatives, confidence, limitations, impact boundaries, and follow-up needs.
Output: Timeline findings and reviewer package.
Fake Dashboard
Training dashboard for supplied fictional evidence only.
Sources normalized
8
File, process, identity, application, cloud, network, deployment, and business records are mapped.
Timeline events
12
Every fictional event preserves original time, normalized time, source, relationship, confidence, and limitation.
Open correlation conflicts
1
Exact file-event ordering remains a one-minute range because of source resolution.
Fake SOC Alert
Source: Fake Timeline Correlation Console • Time: 09:38 AM
Fake Log Panel
09:14:36 ID session='SVC-22' identity='archive-export-service' 09:15:42 PROCESS worker='archive-export-worker' job='441' 09:16:08 PROCESS child='copy-worker' target='approved-copy' 09:16:11 FLOW destination='archive-storage-api.internal' state='allowed' 09:17:00 FILE creation='duplicate paths begin' resolution='seconds' 09:17:14 STORAGE object_write='first duplicate file complete' 09:18:03 CLOUD public_share='none' external_download='none' 09:20:05 APP event='copy complete' receipt='09:32:09' 09:28 SUPPORT app='archive-review' target='approved folder' 09:38 HEALTH app_delivery='delayed_12m' repair='assigned' 09:54 CORRELATE mechanism='approved worker with outdated config' 09:58 TIMELINE version='v2' changed_events='T-03,T-06,T-09' 10:02 DEPLOY config='corrected' validation='approved' 10:06 FINDING external_disclosure='not supported within coverage' 10:10 REVIEW source_independence='verified' duplicate_views='marked'
Training note: this is fake data for defensive analysis practice only.
Source Health
Time behavior
UTC-04:00; second-level resolution
Coverage
Approved and duplicate folder paths, five files each, creation and modification fields.
Limitation
Copy behavior may reset creation values while preserving modification values.
Correlation role
Direct artifact timing and content-identity evidence.
Time behavior
Captured 09:24:10 UTC-04:00
Coverage
Process tree, sessions, arguments, open handles, modules, and internal connections.
Limitation
Represents one moment and omits earlier or later process state.
Correlation role
Runtime mechanism and process relationship evidence.
Time behavior
UTC with millisecond resolution
Coverage
Service-session start, role, token lifecycle, and approved identity context.
Limitation
Service identity does not prove human intent or every action.
Correlation role
Identity and session correlation.
Time behavior
UTC; second-level event time and separate receipt time
Coverage
Job start, copy operation, retry state, result, configuration, and completion.
Limitation
Initial arrival order was not the same as event order.
Correlation role
Workflow and job-level confirmation after repair.
Time behavior
UTC; second-level resolution
Coverage
Object operations, sharing, public links, downloads, permissions, and administrative actions.
Limitation
Conclusion remains bounded by retention, account, platform, and approved time window.
Correlation role
Impact and cloud-action boundary.
Time behavior
UTC-04:00; second-level start and duration
Coverage
Source process route, internal storage destination, protocol, bytes, and duration.
Limitation
Does not reveal full payload or application meaning.
Correlation role
Internal connection and destination correlation.
Time behavior
UTC; minute-level approval and second-level startup records
Coverage
Approved version, outdated configuration reference, rollout, correction, and restart.
Limitation
Repository state requires runtime confirmation.
Correlation role
Configuration and root-condition timing.
Time behavior
Coverage
Limitation
Identity context does not prove every later action.
Correlation role
Time behavior
Coverage
Limitation
Application record arrived later but preserved the earlier event time.
Correlation role
Time behavior
Coverage
Limitation
Snapshot does not capture the entire process lifetime.
Correlation role
Time behavior
Coverage
Limitation
Flow records do not reveal full payload content.
Correlation role
Time behavior
Coverage
Limitation
Second-level field display and platform copy behavior require a range.
Correlation role
Time behavior
Coverage
Limitation
Storage record covers object completion, not human intent.
Correlation role
Time behavior
Coverage
Limitation
Negative conclusion remains bounded by platform and time-window coverage.
Correlation role
Time behavior
Coverage
Limitation
Receipt order must not be mistaken for event order.
Correlation role
Time behavior
Coverage
Limitation
Does not prove full human viewing of every file.
Correlation role
Time behavior
Coverage
Limitation
Earlier timeline version had reduced confidence until repair.
Correlation role
Time behavior
Coverage
Limitation
Recovery validation belongs to the incident-response record, not proof of prior intent.
Correlation role
Versioned Timeline
Original
09:14:36 UTC-04:00
Normalized
13:14:36 UTC
Event
Approved fictional archive-export service session SVC-22 begins.
Relationship
Provides service context for job 441.
Limitation
Identity context does not prove every later action.
Original
09:15:42 UTC-04:00
Normalized
13:15:42 UTC
Event
Scheduler launches archive-export-worker for job 441 using export-legacy configuration.
Relationship
Connects approved scheduling to the outdated runtime configuration.
Limitation
The application record arrived later but preserved the earlier event time.
Original
09:16:08 UTC-04:00
Normalized
13:16:08 UTC
Event
Export worker launches child copy-worker with target approved-copy.
Relationship
Strongest runtime link to the duplicate-folder mechanism.
Limitation
The snapshot does not capture the full process lifetime.
Original
09:16:11–09:16:48 UTC-04:00
Normalized
13:16:11–13:16:48 UTC
Event
Copy-worker communicates with the internal archive-storage API.
Relationship
Supports an internal service route during the copy operation.
Limitation
Flow records do not reveal full payload content.
Original
09:17:00 UTC-04:00
Normalized
13:17:00–13:17:59 UTC
Event
Duplicate-folder creation values begin appearing.
Relationship
Consistent with a later duplicate-path creation event.
Limitation
Source resolution and platform copy behavior require a range.
Original
09:17:14 UTC-04:00
Normalized
13:17:14 UTC
Event
First duplicate-file write completes under job 441.
Relationship
Corroborates the process target and file metadata.
Limitation
The record supports object completion, not human intent.
Original
09:18:03 UTC-04:00
Normalized
13:18:03 UTC
Event
No public-link or external-share setting is created in the approved window.
Relationship
Narrows supported cloud impact within verified coverage.
Limitation
The conclusion remains bounded by platform and time-window coverage.
Original
09:20:05 UTC event / 09:32:09 UTC receipt
Normalized
09:20:05 UTC event
Event
Application records completion of the job 441 copy operation.
Relationship
Confirms the workflow after delayed delivery is resolved.
Limitation
Receipt order must not be mistaken for event order.
Original
09:38 local
Normalized
13:38 UTC
Event
The application-audit delivery delay is identified and assigned for repair.
Relationship
Explains why application events appeared after file and process records.
Limitation
Timeline version 1 had reduced confidence until repair.
Original
10:02 local
Normalized
14:02 UTC
Event
The outdated configuration is replaced and corrected validation is approved.
Relationship
Provides the corrective transition after the forensic finding.
Limitation
Recovery validation does not prove earlier human intent.
Findings Matrix
Evidence support
Independent identity, process, application, and business-schedule records.
Alternative
Manual execution is not supported by the supplied session or command records.
Limitation
Service identity does not identify human intent.
Evidence support
Process arguments, application job, storage transaction, file metadata, deployment state, and internal network flow.
Alternative
Synchronization or manual copying remain possible but receive less support.
Limitation
The process snapshot represents one moment and exact activation start depends on deployment correlation.
Evidence support
Separate application event and receipt times, source-health record, process start, storage transaction, and file creation range.
Alternative
Clock drift was considered but not supported by source synchronization checks.
Limitation
The file source supports a one-minute range rather than a single exact ordering point.
Evidence support
Process-to-flow association, internal destination, DNS, firewall, and application service mapping.
Alternative
Unrecorded activity outside verified coverage cannot be completely excluded.
Limitation
Flow data does not reveal full payload content.
Evidence support
Cloud audit, identity, network, application, support, and business records.
Alternative
Events outside retention, platform, account, or approved time boundaries remain outside the conclusion.
Limitation
This is a bounded no-supported-evidence statement, not proof of impossibility.
Evidence support
Application completeness validation, event-versus-receipt distinction, reviewer record, and preserved prior version.
Alternative
No competing timeline better explains the independent evidence set.
Limitation
Future approved evidence could still require another revision.
Analyze the Evidence
Common Mistakes
Safe Practice Lab
Your fictional assignment
Use only the supplied fictional Northbridge records to create a complete source map, normalized timeline, conflict register, findings matrix, and revision history.
Required deliverables
Scenario Decision Lab
The fictional application event time fits the file, process, and storage sequence, but the record was received twelve minutes later.
Scenario Decision Lab
A fictional cloud dashboard, CSV export, screenshot, and leadership summary all show no public-link creation.
Defender Habits
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Portfolio Prompt
Create a fictional Network, Cloud, and Timeline Correlation Package for the Northbridge Research Archive case. Include source inventory, source-health records, original event times, normalized times, conversion methods, clock and delay notes, source-independence map, duplicate views, correlation windows, conflict records, alternatives, timeline versions 1 and 2, findings, confidence, limitations, impact boundaries, reviewer decisions, revision history, and a portfolio-safety statement.
Key Takeaways
Navigation