IT Forensics · Business
How can an attacker’s persistence in an IT environment be demonstrated?
Persistence can be achieved via services, scheduled tasks, autostarts, accounts, cloud tokens or other mechanisms.
Why this question is important for a business
Following a cyberattack, technical, economic, data protection and regulatory decisions may all depend on the same set of facts. A robust reconstruction must therefore clearly distinguish between proven activity, technical feasibility and mere conjecture.
Technical investigative approach
We examine system-specific persistence artefacts and correlate their creation, use and modification with the chronology of the attack.
Where the limits of what can be said lie
An unusual autostart entry or account is not automatically malicious; a distinction must be made between legitimate administration and software installation.
Why LanCologne?
Following a cyber attack, a company’s immediate priority is to ensure security and business continuity. However, for subsequent decisions, it is not enough simply to know that ‚an attack has taken place‘. Senior management, data protection officers, legal advisers, insurers and, where applicable, the authorities require reliable answers to specific factual questions.
LanCologne therefore distinguishes between discovery, initial access, compromise, persistence, lateral movement, data access, potential exfiltration and actual damage. These phases may be separated by significant time intervals and must not be equated with one another.
Where possible, key findings are cross-referenced against several independent data sources. Endpoint, network, identity, cloud and system data each have their own limitations in terms of what they can reveal. For us, an automated alert or a product report is not the source of evidence in itself, but rather a starting point for verifying the underlying primary data.
Counter-hypotheses are also part of the investigation. An unusual login, for example, may be explained by legitimate administration, VPN infrastructure, automated services or compromised login credentials. Only by correlating further evidence can a reliable conclusion be reached.
If crucial data is missing, this gap is not filled with speculation. Particularly in the case of cyber incidents, the statement ‚cannot be determined with certainty on the basis of the data received‘ is of greater technical value than an apparently clear account of the attack that cannot be substantiated in a way that can be reproduced.
How we work
Incident response and forensics have different but complementary objectives
The primary aim of containing an ongoing attack is to protect the organisation. Forensic reconstruction then clarifies – either subsequently or in parallel – what actually happened. Necessary security measures are therefore not withheld simply to preserve an ideal state of evidence; unavoidable changes are documented as far as possible.
Why LanCologne following a cyberattack?
LanCologne does not base its investigation on a hypothetical sequence of events. What matters is what technical conclusions can actually be drawn from the primary data obtained. Findings that are incriminating, exonerating or inconclusive are documented in a transparent manner so that the management and legal advisers can make decisions based on verifiable facts.
Legal framework
Article 32 of the GDPR requires data controllers and data processors to ensure a level of protection appropriate to the risk. Among other things, it refers to confidentiality, integrity, availability and resilience, as well as the ability to restore availability and access promptly following a technical or physical incident.
If a cyber incident has resulted in a personal data breach, Article 33 of the GDPR may apply. According to this provision, a breach subject to notification must, in principle, be reported to the competent supervisory authority without undue delay and, where possible, within 72 hours of it coming to light, provided that it is not likely to result in a risk to the rights and freedoms of natural persons. Article 33(5) also requires the breach, its effects and the remedial measures taken to be documented. Where a high risk is likely, Article 34 of the GDPR may additionally require the data subjects to be notified. Whether these conditions are met is a matter for assessment under data protection law; IT forensics provides the technical facts for this purpose.
Since 6 December 2025, the revised BSI Act, which implements the NIS 2 requirements, has applied to certain private companies. Whether a company is classified as a particularly important or important organisation must be assessed on a case-by-case basis in accordance with the current BSI Act, taking into account the sectors, types of organisation and size criteria. For covered organisations, the BSIG sets out, amongst other things, obligations regarding cybersecurity risk management and security incidents; Section 38 of the BSIG assigns obligations to the management of particularly important and important organisations to implement and monitor risk management measures.
Statutory reporting and documentation obligations may be time-sensitive. However, LanCologne does not make any definitive legal determinations regarding reporting obligations, responsibility or liability. We provide the technically verifiable factual basis on which management, data protection officers and legal advisers can make decisions.
Frequently Asked Questions
How can an attacker’s persistence in an IT environment be demonstrated?
How is such a technical investigation carried out in practice?
Does the investigation always produce a clear-cut result, either for or against a person involved?
Is there a legal basis for this?
If a cyber incident has resulted in a personal data breach, Article 33 of the GDPR may apply. According to this provision, a breach subject to notification must, in principle, be reported to the competent supervisory authority without undue delay and, where possible, within 72 hours of it coming to light, provided that it is not likely to result in a risk to the rights and freedoms of natural persons. Article 33(5) also requires the breach, its effects and the remedial measures taken to be documented. Where a high risk is likely, Article 34 of the GDPR may additionally require the data subjects to be notified. Whether these conditions are met is a matter for assessment under data protection law; IT forensics provides the technical facts for this purpose.
Since 6 December 2025, the revised BSI Act, which implements the NIS 2 requirements, has applied to certain private companies. Whether a company is classified as a particularly important or important organisation must be assessed on a case-by-case basis in accordance with the current BSI Act, taking into account the sectors, types of organisation and size criteria. For covered organisations, the BSIG sets out, amongst other things, obligations regarding cybersecurity risk management and security incidents; Section 38 of the BSIG assigns obligations to the management of particularly important and important organisations to implement and monitor risk management measures.
Statutory reporting and documentation obligations may be time-sensitive. However, LanCologne does not make any definitive legal determinations regarding reporting obligations, responsibility or liability. We provide the technically verifiable factual basis on which management, data protection officers and legal advisers can make decisions.
🔗 Related topics
LanCologne – IT Forensics for Businesses
Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.
Related to this topic
- How can a company determine whether security software has been disabled by an attacker?
- How can a complete chronology of the attack be compiled following a cyber incident?
- In the event of a ransomware attack, how can a company distinguish between the initial compromise and the encryption?
- How can the actual scope of a ransomware attack be determined?