skip to content

A CERT's intrusion tip finds no support in your surviving logs — can you close it as unfounded?

level: middleimportance: must knowfreq 66%

answer

  1. not looked versus could not see
  2. retention, coverage, fidelity
  3. absence of evidence is not evidence of absence
  4. declaring is a posture, not a verdict
  5. bound the negative to one source

basics

~20 s

No. First separate 'we looked and it is not there' from 'we could not have seen it'. A search is only evidence where a source covered that host and window, retained the data, and would have recorded the described activity.

solid answer

~50 s

A null result is only meaningful inside the coverage of the sources you searched. I write down, per source, three things: retention — did it still hold the claimed window; coverage — was the host, subnet or account actually instrumented then; and fidelity — would that record type have carried the described behaviour at all. Where all three hold and nothing appeared, that is genuine negative evidence, bounded by that source. Where any fails, the search answered nothing and saying otherwise is the mistake. In the meantime I keep the case open and act as though the report is true for response purposes: preserve what survives, put a hold on the rest, and ask the reporter for one more searchable discriminator. Declaring an intrusion on someone else's word is a working posture that authorises preservation and containment, and it can be downgraded later with a written rationale.

go deeper

for a junior

Remember the phrase and the reason: absence of evidence is not evidence of absence. Before reporting a clean search, check that the logs you searched actually covered the host and the dates in the report.

for a middle

Be able to break a null result down into retention, coverage and fidelity, and to give a concrete example of each — a window past retention, an agent that was not installed, and a record type that could not have carried the behaviour.

for a senior

Show that you act before you can prove: preserve and hold immediately, run the case as a suspected intrusion, and pivot to artefacts that outlive logs when the primary window is gone.

for a principal

Own the consequence — repeated unsearchable windows are a collection strategy problem, and the argument for retention and coverage investment is best made with the specific tips you could not answer.

## The mistake this question exists to catch 'We searched and found nothing, so it did not happen' is the single most common wrong answer in this scenario. It quietly converts *absence of evidence* into *evidence of absence*, and in security that conversion is almost never licensed, because the collection layer is partial by design and the intruder had every incentive to operate where it is thin. The useful discipline is to ask, of each source you searched, whether it could have answered the question at all. Three properties decide it. ### 1. Retention Did the source still hold the claimed window when you ran the search? Outside notifications arrive late — weeks or months after the observation — and perimeter and proxy logs are commonly the shortest-lived data you own. If the window predates retention, the query returned zero rows because there were no rows, which is not a statement about your estate. Note that retention is often uneven: a hot searchable tier of days sitting in front of a colder archive of months, or a SIEM feed that started only after a given host was onboarded. ### 2. Coverage Was the thing being described instrumented at that time? Concretely: was the endpoint agent installed and healthy on that host, was that subnet inside the flow-collection footprint, was that SaaS tenant's audit trail even enabled, was flow sampled rather than complete. A source that was silent because the collector had been dead for a fortnight looks identical, in a query result, to a source that was silent because nothing happened. This is why a healthy operation monitors for *sources that stopped reporting* independently of any detection. ### 3. Fidelity Would that record type have carried the described behaviour even under perfect coverage? A flow record proves bytes moved and carries no payload, so it can never corroborate a claim about *what* was sent. A DNS query log shows the name asked for, not what the resolver returned to the process. A native Windows process-creation record carries the command line only where audit policy was configured to include it, so a claim about how a tool was invoked can be invisible in a log that faithfully recorded the execution. Searching the wrong record type and reporting a clean result is a fidelity failure, not a finding. ## What you can honestly write The write-up is per source, not global. Something like: endpoint telemetry covered 96% of the fleet with 90 days of retention, fully spanning the window, and no matching activity appeared; edge firewall logs retained only 7 days and could not be searched for that window; the SaaS audit trail was enabled two weeks after the reported activity. That paragraph is defensible, it is honest about what remains unknown, and it lets a reader see exactly where an intrusion could still hide. A single sentence saying 'no evidence of compromise was found' hides all of it, and readers will hear it as 'no compromise occurred'. ## What you do while you cannot corroborate You do not sit still waiting for proof. Practical moves: - **Preserve first.** Extend retention or export the surviving window immediately; every day you deliberate, more of the answer expires. - **Treat the report as true for response purposes.** Declaring on a third party's word is a working posture, not a finding of fact. It unlocks preservation, containment authority and the people you need; it can be downgraded later, in writing, with the reasoning recorded. - **Go back to the reporter for one more discriminator.** A source they will not burn is still compatible with them giving you a second timestamp, a destination, a port, a file hash or an account name. Frame the ask as 'anything I can search', not 'how did you see this'. - **Pivot to artefacts that outlive logs.** Persistence on candidate hosts, account and credential state, unexpected service accounts, group memberships, configuration drift, backups, and cloud control-plane history that is retained longer than host logs. Consequences frequently survive the records of their creation. - **Fix the gap you just discovered.** A window you could not search is a finding in its own right, and it will recur on the next tip. ## Where a clean result is real None of this means negatives are worthless. If the endpoint agent demonstrably ran on that host for the whole window, retained the data, and records exactly the behaviour class described, then its silence *is* evidence — for that host, that window, that behaviour. State the bound explicitly, and let the strength of the claim follow the strength of the coverage rather than the strength of your relief.

  • What would make a negative search result genuine evidence rather than a gap?
    Three things together: the source demonstrably covered that host or account for the whole window, it retained the data through to your search, and its record type would have captured the described behaviour. Then its silence is real evidence — for that source, that scope, that window. State the bound in the same sentence as the conclusion, because a negative reported without its coverage is read as a global all-clear.
  • The reported hour predates your retention entirely — what do you do instead of searching?
    Look for consequences that outlive records. Persistence mechanisms and unexpected scheduled tasks or services on candidate hosts, accounts and group memberships created in that period, credential and key material that should have changed, configuration drift, backups from around the window, and control-plane history in cloud or SaaS where retention is often far longer. Then say plainly that the primary window was unsearchable.
  • Can you declare an intrusion when your own telemetry has corroborated nothing?
    Yes, provisionally, and it is often correct. A declaration is the posture that authorises preservation, containment and the resourcing you need, not an assertion that you have proved anything. Record what it is based on, what would confirm or dissolve it, and the fact that it is revisable. Downgrading later with a written rationale is a normal outcome, not an embarrassment.

A camera that was switched off does not testify that the corridor was empty. Before you cite the footage, you have to show the camera was running, pointed at the corridor, and kept the tape.

saying these in an interview costs you the question

  • Says no hits therefore no compromise
  • Closes the case because no alert ever fired
  • Treats a window past retention as a clean window
  • Reports a global all-clear from one source
  • Labels a third party's observation a false positive
  • Waits for corroboration before preserving anything

context