Within UFO Hackers

How Can a UFO Hacking Story Be Verified?

A credible assessment checks provenance, metadata, contemporaneous records, technical plausibility, and independent corroboration before interpretation.

134 sources 3 graphics
Preview for How Can a UFO Hacking Story Be Verified?

On this page

  • Confirming access and provenance
  • Testing files and technical context
  • Separating testimony from corroboration

Introduction

A UFO hacking story should be tested as two separate claims: first, that unauthorised access really occurred and produced particular files; second, that those files genuinely support an extraordinary interpretation. Evidence for the intrusion does not automatically authenticate what the intruder says was seen. In Gary McKinnon’s case, official records substantiate allegations that he accessed numerous United States government computers, while his best-known UFO discoveries remain recollections without publicly available original files, screenshots or independently verified copies.[parliament.uk]publications.parliament.ukUK Parliament House of LordsUK ParliamentHouse of Lords - Mckinnon V Government of The United…July 30, 2008 — 30 Jul 2008 — between 1 February 2001 and 19 March 2…Published: July 30, 2008

Overview image for Claim Checklist

A credible assessment therefore begins with provenance, contemporaneous records and technical reconstruction, not with arguments about aliens. The key questions are practical: Can the access be independently confirmed? Can the alleged material be traced to a particular system and time? Has it been preserved without alteration? Does its ordinary institutional meaning fit the claimant’s interpretation? Only after those questions are answered should anyone consider more exotic explanations.

Confirm the access before judging the discovery

The first task is to establish what the alleged hacker could actually reach. A convincing account should identify the organisation, system, host, account, approximate time, access method and directories or applications involved. Vague statements such as “I entered a NASA database” are difficult to test because large agencies operate many networks with different purposes, classifications and security controls.

The strongest confirmation usually comes from records created independently of the claimant:

  • authentication and account logs;
  • firewall, proxy and virtual private network records;
  • intrusion-detection alerts;
  • server and application logs;
  • forensic images of the claimant’s computer;
  • command histories, recovered temporary files or saved credentials;
  • incident tickets, internal emails and contemporaneous investigative notes;
  • court documents specifying machines, dates and alleged actions.

Modern incident-response guidance treats logs as evidence that must be collected, correlated and protected because they can show which account connected to which service, from where and when. It also warns that electronic records can be altered, so their integrity and handling history must be demonstrable.[CISA]cisa.govbest practices event logging and threat detectionIt was developed by the Australian Signals Directorate.Read more…

Access is not the same as access to the claimed material

An official acknowledgement of a breach may prove that an intruder entered a network without proving that every later-described document was present there. Investigators should map each claimed discovery to a specific evidential trail. If someone says that a spreadsheet was opened, for example, useful corroboration might include the file path, filename, server identity, access timestamp, local artefacts created by the viewing software and corresponding server logs.

This distinction matters in the McKinnon case. The House of Lords judgment records the United States allegation that he gained unauthorised access to 97 government computers between February 2001 and March 2002. The indictment and related official material concern computer access and alleged damage; they do not independently authenticate his descriptions of a “Non-Terrestrial Officers” file or an anomalous spacecraft image.[parliament.uk]publications.parliament.ukUK Parliament House of LordsUK ParliamentHouse of Lords - Mckinnon V Government of The United…July 30, 2008 — 30 Jul 2008 — between 1 February 2001 and 19 March 2…Published: July 30, 2008

That leaves several logically distinct possibilities: he may have seen exactly what he later described; he may have accurately remembered a real file but misunderstood its purpose; he may have combined details from different systems or sessions; or his memory may have changed over time. Confirmation of the intrusion narrows the dispute, but it does not resolve it.

Claim Checklist illustration 1

Preserve provenance before interpreting files

Provenance is the documented history of where evidence came from and what happened to it afterwards. For digital material, this should begin with acquisition of the original device, storage medium or server data, followed by a reproducible forensic copy. Investigators normally calculate cryptographic hash values—digital fingerprints used to detect later changes—and record every transfer, examination and extraction.

The United States National Institute of Standards and Technology describes digital forensics as collection, examination, analysis and reporting carried out while preserving data integrity. Its guidance stresses proper labelling, recording, chain of custody and storage, because confidence in a conclusion depends partly on confidence that the examined evidence is the same evidence originally collected.[NIST]nist.govOpen source on nist.gov.

For a UFO hacking claim, a useful provenance record would answer:

  1. Who acquired the file, and from what machine or storage location?
  2. Was it copied directly, photographed on screen or reconstructed later?
  3. What was its original filename, path, format and hash?
  4. Were the source computer’s clock and time zone known to be accurate?
  5. Who handled the evidence after acquisition?
  6. Is the original still available for independent examination?
  7. Can another examiner reproduce the extraction and findings?

A screenshot is better than memory, but it is weaker than the original file with its surrounding directory, metadata and system records. A retyped list is weaker still because spelling, headings, column structure and hidden fields may have been lost. A photograph of a monitor can establish what appeared on a display, yet it may not reveal whether the underlying file was authentic, mislabelled, staged or opened from another source.

Missing evidence changes the strength, not necessarily the sincerity, of a claim

The absence of a preserved file does not prove fabrication. Early-2000s remote access was slow, storage habits were inconsistent, intruders were trying to avoid detection, and a connection could end before material was saved. McKinnon told Wired that he saw only part of a large image through a low-bandwidth remote session and was disconnected before securing it; he also acknowledged uncertainty about whether another claimed document might have had a more conventional purpose.[WIRED]wired.comufo hacker tells what he foundWIRED'UFO Hacker' Tells What He Found21 Jun 2006 — The search for proof of the existence of UFOs landed Gary McKinnon in a world of troub…

Nevertheless, lost evidence cannot be examined simply because there is a plausible reason for its loss. The proper classification is “unverified testimony”, not “disproved” and not “confirmed”. A fair assessment can regard a witness as sincere while assigning little evidential weight to an unrecoverable image or document.

Test the files and their technical setting

Once a file is available, its contents should not be interpreted in isolation. Examiners first ask whether its format, metadata, directory location, naming conventions and software history are consistent with its claimed origin.

Relevant checks include:

  • file creation, modification and access times;
  • document author, organisation and software fields;
  • embedded thumbnails and revision histories;
  • spreadsheet formulas, hidden sheets, comments and linked files;
  • image dimensions, compression history and colour profile;
  • server path, permissions and neighbouring files;
  • deleted fragments or earlier versions;
  • whether the application and file format existed at the claimed date;
  • whether the document matches known agency templates or terminology.

Metadata can help identify a source or processing history, but it is supporting evidence rather than a seal of authenticity. The Scientific Working Group on Digital Evidence notes that metadata may be limited, absent or altered. The European Network of Forensic Science Institutes similarly recommends combining context, source, integrity, processing and manipulation analysis rather than relying on a single indicator.[SWGDE - SWGDE]swgde.orgBest Practices for Image AuthenticationBest Practices for Image Authentication

Claim Checklist illustration 2

An unusual label may have an ordinary institutional meaning

Words that sound extraordinary outside an organisation may be routine jargon within it. “Non-terrestrial”, for example, could refer literally to something beyond Earth, but it might also describe space-related duties, personnel not assigned to terrestrial commands, a planning scenario, a fictional exercise, an internal category or an informal working title. The document’s schema, associated offices, distribution list and neighbouring records would be needed to distinguish those possibilities.

The correct question is therefore not merely “Does this phrase sound remarkable?” but “How was this phrase used by that organisation at that time?” Useful tests include searching declassified records, manuals, procurement documents, personnel classifications and archived organisational charts. A mundane explanation should not be accepted automatically, but it must be investigated before an exotic one is preferred.

Image claims require the same discipline. An apparent craft may instead be a satellite, debris, processing artefact, glare, cloud feature, calibration target or composite element. Analysts need the original pixels, acquisition system, viewing geometry, exposure data and processing history. Visual resemblance alone cannot establish scale, distance or physical nature.

NASA’s independent UAP study reached a comparable conclusion about anomalous imagery generally: reliable interpretation is hindered when sensor calibration, multiple measurements, metadata and baseline data are missing. It recommended observations from multiple well-calibrated sensors because a striking image without technical context often cannot support a firm identification.[NASA Science]science.nasa.govOpen source on nasa.gov.

Reconstruct whether the story is technically plausible

A claim can be sincere and still contain impossible or anachronistic details. Investigators should reconstruct the alleged session using the hardware, bandwidth, operating systems and software available at the time.

For an early remote-access account, questions might include:

  • Could the stated connection speed have transferred a file of the claimed size within the available time?
  • Did the remote-control software support the described colour depth, resolution and screenshot behaviour?
  • Would viewing a file have created a cache, recent-file entry, thumbnail or swap-file trace?
  • Could the user account reach the alleged server or directory?
  • Was the claimant likely to know which organisation owned the machine?
  • Would the described interface, filename conventions and application versions have existed then?
  • Could a disconnection have produced the exact partial display described?

Technical plausibility is not proof, but it identifies contradictions and shows what traces should exist. If a story predicts local cache files, server logs and a recently opened document entry, and none survives despite comprehensive forensic recovery, confidence should fall. If independent artefacts align with the account, confidence should rise.

Investigators must also avoid judging old incidents by present-day systems. Networks in the late 1990s and early 2000s often had weaker password practices, less centralised logging and shorter retention periods than modern environments. Missing logs decades later may therefore be unsurprising. The evidential consequence remains the same: where records no longer exist, the claim may be impossible to resolve conclusively.

Separate testimony from corroboration

Testimony answers what a person says they saw. Corroboration answers whether something independent supports it. These should be displayed separately rather than blended into a single narrative.

A practical evidence ladder is:

Strongly corroborated: Original files are preserved; hashes and chain of custody are documented; source-system logs match; independent examiners reproduce the result; institutional context supports the claimed meaning.

Partly corroborated: The intrusion and relevant system access are confirmed, but only copies or incomplete artefacts survive; some metadata and contemporaneous notes align with the account; interpretation remains disputed.

Unverified but testable: A detailed account identifies systems, dates and filenames, but authorities or custodians have not released the relevant records.

Unverified and weakly testable: The claim rests on recollection without files, screenshots, precise paths or contemporaneous notes.

Contradicted: Technical details are impossible, records place the claimant elsewhere, the file post-dates the incident, or the alleged source demonstrably did not host the material.

This framework prevents two common errors. Believers sometimes treat proof of unauthorised access as proof of the UFO interpretation. Sceptics sometimes treat the absence of a saved file as proof that the witness invented the entire story. Neither inference is justified without additional evidence.

Claim Checklist illustration 3

Consistency helps, but independence matters more

A story repeated consistently over many interviews may indicate stable memory or a fixed account. It does not create new corroboration when later articles merely quote earlier ones. Researchers should trace each reported detail back to its earliest known source and identify whether later witnesses had access to that account.

Independent corroboration is strongest when it was recorded before the claim became public. Examples include a server administrator’s dated incident report mentioning the same unusual filename, a forensic image containing a corresponding fragment, or an internal email noting access to the relevant directory. A later statement from someone who has heard the public story may be supportive, but it is more vulnerable to suggestion and retrospective alignment.

Official silence is also ambiguous. An agency may decline to discuss a file because it does not exist, because records have been destroyed, because an investigation remains sensitive, or because acknowledging the system would reveal security information. Silence should not be converted into either confirmation or disproof.

Apply a disciplined decision rule

The final judgement should state precisely what has been established, what remains possible and what evidence is missing. A careful assessment might read:

The unauthorised access is independently documented. The claimed UFO-related material is described only in later testimony and is not available for forensic examination. The account is technically possible in broad outline, but its specific contents and extraordinary interpretation remain uncorroborated.

That formulation is more informative than labelling the entire story “true” or “false”. A UFO hacking claim contains multiple propositions, and each may deserve a different confidence level.

Before treating such a story as verified, look for five converging elements:

  1. Confirmed access: independent records place the claimant on the relevant system.
  2. Traceable provenance: the material can be linked to its original source and handling history.
  3. Forensic integrity: original files or defensible copies survive and have been examined.
  4. Contextual plausibility: the terminology and content fit the organisation, period and system.
  5. Independent corroboration: evidence not derived from the claimant supports both the discovery and its interpretation.

Failure at one stage does not automatically invalidate every other stage. It does, however, limit the conclusion. In cases such as Gary McKinnon’s, the evidence can support a documented hacking episode and a sincerely maintained account of unusual discoveries while still falling far short of verifiable proof that government computers contained evidence of extraterrestrial craft or personnel.

Amazon book picks

Further Reading

Books and field guides related to How Can a UFO Hacking Story Be Verified?. Use these as the next step if you want deeper reading beyond the article.

BookCover for The UFO Enigma

The UFO Enigma

By Peter A. Sturrock

"A comprehensive investigation of encounters with unidentified flying objects, all the more riveting because it is both skeptical and scr...

BookCover for Real-Life X-Files

Real-Life X-Files

By Joe Nickell

"Excellent background research . . . on-site investigations of mysteries ranging from crop circles and lake monsters to spiritualist medi...

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromUFO poster oneBay.co.uk.

Endnotes

1. Source: publications.parliament.uk
Title: UK Parliament House of Lords
Link:https://publications.parliament.uk/pa/ld200708/ldjudgmt/jd080730/mckinn-1.htm

Source snippet

UK ParliamentHouse of Lords - Mckinnon V Government of The United...July 30, 2008 — 30 Jul 2008 — between 1 February 2001 and 19 March 2...

Published: July 30, 2008

2. Source: justice.gov
Link:https://www.justice.gov/archive/usao/nj/Press/files/pdffiles/Older/edva_mckinnon_indictment.pdf

3. Source: wired.com
Title: ufo hacker tells what he found
Link:https://www.wired.com/2006/06/ufo-hacker-tells-what-he-found/

Source snippet

WIRED'UFO Hacker' Tells What He Found21 Jun 2006 — The search for proof of the existence of UFOs landed Gary McKinnon in a world of troub...

4. Source: cisa.gov
Title: best practices event logging and threat detection
Link:https://www.cisa.gov/resources-tools/resources/best-practices-event-logging-and-threat-detection

Source snippet

It was developed by the Australian Signals Directorate.Read more...

5. Source: cisa.gov
Link:https://www.cisa.gov/sites/default/files/2024-08/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf

Source snippet

Table 1 below presents an example of logs and event data that are commonly employed to...Read more...

6. Source: nvlpubs.nist.gov
Link:https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-86.pdf

Source snippet

NIST PublicationsNIST SP 800-86, Guide to Integrating Forensic Techniques into Incident Response...

7. Source: nist.gov
Link:https://www.nist.gov/itl/csd/secure-systems-and-applications/computer-forensics-tool-testing-program-cftt/digital

9. Source: swgde.org
Title: Best Practices for Image Authentication
Link:https://www.swgde.org/documents/published-complete-listing/18-i-001-best-practices-for-image-authentication/

10. Source: science.nasa.gov
Link:https://science.nasa.gov/wp-content/uploads/2023/09/uap-independent-study-team-final-report.pdf

11. Source: nist.gov
Link:https://www.nist.gov/digital-evidence

12. Source: nist.gov
Link:https://www.nist.gov/

13. Source: nvlpubs.nist.gov
Link:https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8387.pdf

14. Source: nist.gov
Link:https://www.nist.gov/standard/3351

15. Source: nist.gov
Title: digital evidence preservation considerations evidence handlers
Link:https://www.nist.gov/publications/digital-evidence-preservation-considerations-evidence-handlers

16. Source: csrc.nist.gov
Title: govchain of custody
Link:https://csrc.nist.gov/glossary/term/chain_of_custody

17. Source: nist.gov
Link:https://www.nist.gov/forensic-science/interdisciplinary-topics/evidence-management

18. Source: nvlpubs.nist.gov
Title: SP.800 61r2
Link:https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

19. Source: nvlpubs.nist.gov
Title: specialpublication800 61r1
Link:https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-61r1.pdf

20. Source: nvlpubs.nist.gov
Title: specialpublication800 92
Link:https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-92.pdf

21. Source: nvlpubs.nist.gov
Title: NIST.SP.1800 26
Link:https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1800-26.pdf

22. Source: csrc.nist.gov
Title: Cybersecurity Publications.xlsx
Link:https://csrc.nist.gov/CSRC/media/Publications/Shared/documents/NIST-Cybersecurity-Publications.xlsx

23. Source: nvlpubs.nist.gov
Title: specialpublication800 53r4
Link:https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-53r4.pdf

24. Source: nvlpubs.nist.gov
Title: SP.800 82r3
Link:https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r3.pdf

25. Source: nccoe.nist.gov
Title: di detect respond nist sp1800 26 draft
Link:https://www.nccoe.nist.gov/sites/default/files/legacy-files/di-detect-respond-nist-sp1800-26-draft.pdf

26. Source: nvlpubs.nist.gov
Title: specialpublication800 53r1
Link:https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-53r1.pdf

27. Source: science.nasa.gov
Link:https://science.nasa.gov/uap/

28. Source: cisa.gov
Link:https://www.cisa.gov/resources-tools/programs/cisa-international

29. Source: cisa.gov
Link:https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business/use-logging-on-business-systems

30. Source: cisa.gov
Link:https://www.cisa.gov/news-events/alerts/2024/08/21/asds-acsc-cisa-fbi-and-nsa-support-international-partners-release-best-practices-event-logging-and

31. Source: cisa.gov
Link:https://www.cisa.gov/resources-tools/services/logging-made-easy

32. Source: cisa.gov
Link:https://www.cisa.gov/resources-tools/resources?f%5B0%5D=resource_audience%3A130&f%5B1%5D=resource_sector%3A17&f%5B2%5D=resource_topic%3A72&page=9

33. Source: cisa.gov
Link:https://www.cisa.gov/topics/industrial-control-systems

34. Source: cisa.gov
Title: all resources tools
Link:https://www.cisa.gov/resources-tools/all-resources-tools?f%5B0%5D=multiple_resource_audience%3A40&f%5B1%5D=multiple_resource_sector%3A20&f%5B2%5D=multiple_resource_topic%3A111&page=9

35. Source: cisa.gov
Title: enhanced visibility and hardening guidance communications infrastructure
Link:https://www.cisa.gov/resources-tools/resources/enhanced-visibility-and-hardening-guidance-communications-infrastructure

36. Source: cisa.gov
Link:https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-266a

37. Source: cisa.gov
Link:https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-212a

38. Source: medium.com
Link:https://medium.com/the-lindberg-interviews/interview-with-ufo-hacker-gary-mckinnon-5aa5d366828b

39. Source: swgde.org
Link:https://www.swgde.org/documents/published-complete-listing/23-f-004-best-practices-for-digital-evidence-acquisition-preservation-and-analysis-from-cloud-service-providers/

40. Source: GOV.UK
Title: method validation in digital forensics accessible
Link:https://www.gov.uk/government/publications/method-validation-in-digital-forensics/method-validation-in-digital-forensics-accessible

41. Source: GOV.UK
Title: forensic science activities statutory code of practice version 2 accessible
Link:https://www.gov.uk/government/publications/forensic-science-activities-statutory-code-of-practice-version-2/forensic-science-activities-statutory-code-of-practice-version-2-accessible

42. Source: GOV.UK
Title: forensic science regulator code of practice accessible
Link:https://www.gov.uk/government/publications/statutory-code-of-practice-for-forensic-science-activities/forensic-science-regulator-code-of-practice-accessible

43. Source: GOV.UK
Title: digital imaging and multimedia procedure v30
Link:https://www.gov.uk/government/publications/digital-investigations-digital-imaging-and-multimedia-procedure/digital-imaging-and-multimedia-procedure-v30

44. Source: GOV.UK
Link:https://www.gov.uk/government/consultations/forensic-science-draft-statutory-code-of-practice/code-of-practice-consultation-draft-accessible-version

45. Source: GOV.UK
Title: recovery and aquisition of video evidence v30
Link:https://www.gov.uk/government/publications/recovery-and-acquisition-of-video-evidence/recovery-and-aquisition-of-video-evidence-v30

46. Source: GOV.UK
Title: draft statutory code of practice accessible version
Link:https://www.gov.uk/government/publications/forensic-science-regulator-draft-core-statutory-code-for-comment/draft-statutory-code-of-practice-accessible-version

47. Source: GOV.UK
Title: latest on [gary mckinnon case]({{ ‘mc-kinnon-case/’ | relative_url }})
Link:https://www.gov.uk/government/news/latest-on-gary-mckinnon-case

48. Source: Wikipedia
Link:https://en.wikipedia.org/wiki/Digital

49. Source: Wikipedia
Title: Gary Mc Kinnon
Link:https://en.wikipedia.org/wiki/Gary_McKinnon

50. Source: cdn.websitebuilder.service.justice.gov.uk
Link:https://cdn.websitebuilder.service.justice.gov.uk/uploads/sites/64/2026/04/WITN0044001.pdf

51. Source: developer-portal.service.justice.gov.uk
Link:https://developer-portal.service.justice.gov.uk/docs/security-guidance/it-investigations-planning-and-operations-policy/

52. Source: cps.gov.uk
Title: Disclosure Manual: Chapter 30
Link:https://www.cps.gov.uk/prosecution-guidance/disclosure-manual-chapter-30-digital-material

53. Source: media.techtarget.com
Link:https://media.techtarget.com/rms/computerweekly/DowntimePDF/pdf/mckinnon.pdf

54. Source: assets.publishing.service.gov.uk
Title: gs 15 37b forensic science beyond evidence
Link:https://assets.publishing.service.gov.uk/media/5a7f6958e5274a2e87db5b17/gs-15-37b-forensic-science-beyond-evidence.pdf

55. Source: cyber.gov.au
Title: best practices for event logging and threat detection
Link:https://www.cyber.gov.au/business-government/detecting-responding-to-threats/event-logging/best-practices-for-event-logging-and-threat-detection

56. Source: dictionary.cambridge.org
Link:https://dictionary.cambridge.org/us/dictionary/english/digital

Additional References

57. Source: youtube.com
Link:https://www.youtube.com/watch?v=b-3RhyfYk58

Source snippet

The Man Who Hacked the U.S. Government provides a detailed biographical and investigative breakdown of Gary McKinnon's unauthorized acces...

58. Source: media.defense.gov
Title: Mc Kinnon comphacker
Link:https://media.defense.gov/2002/Nov/12/2001711901/-1/-1/1/McKinnon_comphacker.pdf

Source snippet

Department of WarU.S. Department of Justice United States Attorney Eastern...12 Nov 2002 — According to the indictment, between March of...

59. Source: youtube.com
Title: Hacking for UFOs and fighting for his life. Who is Gary Mc Kinnon? | Nord VPN
Link:https://www.youtube.com/watch?v=OImdnvQx7sQ

Source snippet

Ancient Aliens: Hacking NASA Secrets (Season 12, Episode 9) | History...

60. Source: youtube.com
Title: The Man Who Hacked the U.S. Government
Link:https://www.youtube.com/watch?v=ND0zQX1rGdg

Source snippet

Hacking for UFOs and fighting for his life. Who is Gary McKinnon? | NordVPN...

61. Source: researchgate.net
Link:https://www.researchgate.net/publication/387792852_Ensuring_the_Integrity_of_Digital_Evidence_The_Role_of_the_Chain_of_Custody_in_Digital_Forensics

62. Source: linkedin.com
Link:https://www.linkedin.com/pulse/beginners-guide-chain-custody-digital-forensics-yen-ming-chiu-lyzjc

63. Source: facebook.com
Link:https://www.facebook.com/itvnews/posts/a-nasa-report-into-unidentified-flying-objects-ufos-has-found-no-evidence-that-t/686500760179269/

64. Source: linkedin.com
Link:https://www.linkedin.com/pulse/best-practices-event-logging-threat-detection-guide-t7wwe

65. Source: linkedin.com
Link:https://www.linkedin.com/pulse/best-practices-digital-evidence-preservation-tracker-products-pdkie

66. Source: linkedin.com
Link:https://www.linkedin.com/pulse/best-practices-event-logging-threat-detection-andy-curtis-vnrvc