Vietnam Newsroom & Threat Intelligence
Clear sources · Careful assessments
NOTEDo not attribute a ransomware family from a file extension or a single ransom note.Vietnam time · UTC+7
Forensic

Forensic timelines: reconstruct incidents from verifiable timestamps

Combine logs, metadata and storage artifacts into a sourced timeline while retaining gaps and clock discrepancies.

Updated: · Vietnam time (UTC+7)

Illustration of an evidence drive and timestamps on a forensic analysis screen.
AI-generated illustration • Not evidentiary imagery of an incident.
Verified

The foundational method references NIST SP 800-86. A simulated timeline is not presented as data from a real incident.

NIST SP 800-86 describes integrating forensics into incident response. Each timeline entry should be traceable to evidence: collection source, time, operator and working copy.

An attractive timeline does not prove events. Clock differences may change their displayed order. State timezones, system times and correction assumptions.

  • Logins: accounts, connection sources, success/failure and receiving devices.
  • Execution: processes, parent-child relationships, commands and created tasks.
  • Storage: file metadata, filesystem journals and remaining snapshots.
  • Network: VPN, firewall, proxy and recorded data-transfer traffic.
  • Backup: schedules, deletion operations, retention changes and test results.
Technical assessment

“The log records an account login” is an observation. “The attacker used that account” is an interpretation requiring additional facts. They must not be presented with equal certainty.

Missing logs do not prove an absence of activity. Logging may have been disabled, expired or altered. State “no data within the collection scope” and explain limits rather than conclude that activity did not occur.

  • Source inventory and evidence-copy hashes where appropriate.
  • Timeline with timezones, evidence paths and confidence levels.
  • Contradictions or gaps requiring further investigation.
  • Conclusions limited to available evidence, with an update history.
ForensicIncident ResponseNAS
NIST SP 800-86 — Forensics in incident response2006 · Foundational guidance on collecting, examining, analyzing and reporting digital evidence.
MITRE ATT&CK — Enterprise TacticsA behavioral reference framework; attacks do not necessarily follow one sequence.

Each source's scope and date are recorded separately when available. A citation does not independently verify every assessment.

· Initial publication with sources and verification limits.

Corrections policy
T
Tùng TEK

TUNGTEK · IT and data recovery. Focused on technical evidence, data integrity and the ability to resume operations.