In-depth guide
What network forensics is, explained from scratch.
Monitoring tells you that something has failed. Network forensics tells you what happened, where and why, with evidence that someone else can verify.
When a network fails, almost everyone finds out the what: there is no internet, Microsoft 365 will not load, the call drops. Almost nobody finds out the why, the where or the how long. Network forensics is the discipline that answers those three questions with evidence, and this guide explains it from scratch, without taking any prior knowledge for granted.
What network forensics is
Network forensics (or network forensic analysis) means reconstructing what happened on a network during an incident from preserved evidence: the traffic that was flowing, the state of the devices and the exact time of each symptom. Its outcome is not an alert, it is an incident record: an explanation of what happened that someone else can verify.
The term comes from the world of security, where it is used to investigate intrusions: who got in, how and what they took. But the same way of working serves something far more frequent in any business: faults. A line outage, a router that becomes overloaded, a name server that stops responding or a cloud service that goes down also leave a trace, and that trace is what makes it possible to fix them and, if necessary, to make a complaint about them.
Vigilatum does forensics on faults and network quality: why it failed, where and how long it lasted. It is not a tool for investigating intrusions.
Monitoring, observability and forensics are not the same thing
The three words are often mixed up, but they answer different questions:
| Discipline | Question it answers | What it delivers |
|---|---|---|
| Monitoring | Is it working now? | A traffic light and an alert when something stops responding. |
| Observability | How is it behaving? | Metrics, logs and traces to explore the system. |
| Forensics | What happened, where and why? | A record of a specific incident, with preserved evidence. |
Monitoring is essential, but it falls short on the day something fails: when the network recovers, the light turns green again and there is nothing left to show. Forensics starts right there.
What evidence is used
A network forensic analysis relies on several types of evidence. The more of them that are preserved from the same moment, the more solid the conclusion:
- The traffic capture. A copy of the packets that were flowing across the network, which shows who each device was talking to and how the network was responding.
- The device state. How the device’s network was configured and which connections it had open at the instant of the failure.
- The timeline. Measurements with their exact time, before, during and after the incident: when the symptom started, when it was confirmed, when it recovered.
- Integrity. A cryptographic seal calculated when the evidence is taken, which makes it possible to verify later that not a single byte has changed.
The problem of time: ten minutes later, there is nothing left to look at
A network fault is a phenomenon that vanishes. When someone reports that ‘the internet is playing up’, the outage that caused it may have lasted three minutes and ended ten minutes ago. The internet provider looks at the line and sees it working; the IT technician restarts the router and everything seems normal. Nobody is lying, but nobody can prove anything.
That is why useful network forensics cannot start when someone notices the failure: it has to be watching before, so that the moment of failure is already recorded when it is needed.
What it is for in a business
In a business without a networking department, forensics is above all a way to stop arguing and start fixing:
- Complaining to the internet provider with the dates, times, duration and cause of each outage, instead of ‘it keeps dropping out’. How to complain step by step.
- Fixing things sooner. The IT technician gets to the fault knowing what was happening at the moment of the failure, instead of trying to reproduce it.
- Knowing who to call. Whether the failure was inside the office, outside, or in a specific service. Router or ISP?
- Accountability. How many hours were lost in the month, why and who was responsible for each failure.
How Vigilatum applies it
Vigilatum brings that method to businesses without a networking department. A probe at each site monitors the network from the inside, continuously. When a fault is confirmed, the incident record is completed automatically – timeline, cause and evidence from that moment – and sealed. You see on your dashboard what has happened and what to do, and the incident record is ready for your IT technician or for a complaint. We explain it on the network forensics page.
What to ask of a network forensics tool
- That it is watching before the failure, not only afterwards.
- That it measures from inside the network, the way the people who work on it experience it.
- That it says where the failure is, not just that there is one.
- That it keeps the evidence in a way that others can review.
- That it lets you verify the integrity of what it keeps.
- That it states how long it keeps each piece of data, and deletes it afterwards.
Frequently asked questions
Common questions.
Are ‘network forensics’ and ‘network forensic analysis’ the same thing?
Yes: they are two names for the same discipline, reconstructing with evidence what happened on a network during an incident.
Do I need an expert to use it?
To analyse technical evidence in depth, it is best to have an IT technician. But the Vigilatum incident record comes already interpreted: it says where the failure was, how long it lasted and what to do, in plain language.
Can network forensics be used to investigate a cyberattack?
In security, that is what it is used for. Vigilatum focuses on faults and network quality – why it failed, where and how long it lasted – and is not a tool for investigating intrusions.
See what is really happening on your network.
A free pilot with a probe on your real network, with no card and no commitment. We will reply within 24 working hours.