Digital Forensics and Incident Response (DFIR) Framework for Operational Technology (OT)
Eran Salfati, Michael Pease · National Institute of Standards and Technology · NISTIR 8428, 22 June 2022 · 2022
Identifier: NISTIR 8428
Access and status
Cost
Free
Free to read or download at source. No account, no purchase.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
An incident-handling framework for operational technology environments, extending conventional DFIR with event-escalation-based response, OT-specific forensic techniques, and the preparation needed to stand up an OT incident response team. Published as a NIST Interagency Report with DOI 10.6028/NIST.IR.8428.
Who it is for, and when
Read it before an engagement involving ICS, SCADA or plant networks, where you cannot take a device offline and the safety case constrains every forensic decision. It is the right citation for explaining to a client or court why standard IT acquisition steps were not available.
What it does not cover
It is a framework rather than a protocol-level manual: no PLC memory acquisition procedures, no vendor-specific controller instructions, and no treatment of Modbus/DNP3/S7 artefact parsing. It also does not cover safety-instrumented-system engineering or regulatory reporting duties.
Go to the source
Open at nist.gov (opens in a new tab)https://www.nist.gov/publications/digital-forensics-and-incident-response-dfir-framework-operational-technology-ot
Details
- Type
- Standard or guidance
- Written for
- AdvancedAdvanced
- Author
- Eran Salfati, Michael Pease
- Publisher
- National Institute of Standards and Technology
- Version verified
- NISTIR 8428, 22 June 2022
- Year
- 2022
- Identifier
- NISTIR 8428
- Topics
- incident-response, iot, network, evidence-handling, us-federal
- Checked at source
- Standards are revised. Confirm the current revision with the publisher before citing this.
Related entries
A NIST Special Publication that sets out a four-phase forensic process (collection, examination, analysis, reporting) and applies it to four data sources: files, operating systems, network traffic, and applications. It is written for organisations building forensic capability inside an incident response function rather than for law enforcement labs.
The incident response process as a discipline: preparation, detection and initial response, live collection from Windows and Unix, forensic duplication, network evidence, evidence handling, then analysis of hosts, traffic, attacker tools and routers, and report writing.
A law review article by a federal judge who writes extensively on digital evidence, the Reporter to the Advisory Committee on Evidence Rules, and a leading evidence practitioner, written as Rules 902(13) and 902(14) were being adopted. It works through the authentication routes for electronic evidence and explains what the new self-authentication provisions were designed to do.
Blue Team Labs Online
Partly freeA gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.
Investigation in cloud environments using native tooling and logs alongside conventional forensic technique: AWS, Azure and Google Cloud, then Microsoft 365, Google Workspace and containerised environments including Kubernetes, with attention to which logs must be enabled before an incident to be available after one.