Certify web server, database, firewall and application logs for forensic investigations, data breaches, GDPR and NIS2 compliance
When your IT infrastructure has been compromised – web server breached, database illegally accessed, DDoS attack, unauthorized access, data breach – it is fundamental to forensically certify system logs before they are overwritten, rotated or deleted by providers. With forensic server log certification, web access logs, databases, firewalls, applications and systems are acquired according to verifiable technical methodologies, analyzed to identify attack patterns and transformed into an admissible, integral and dated evidence package, suitable for criminal complaints, insurance claims, compliance audits and conforming to legal requirements of the European regulatory framework.
We certify logs from any infrastructure: web servers (Apache, Nginx, IIS, LiteSpeed), databases (MySQL, PostgreSQL, MongoDB), firewalls, CDN/WAF (Cloudflare, Akamai, AWS), operating systems (Linux, Windows), applications. The service is performable remotely via controlled access to management panels or via processing of log files exported by the client, preserving forensic integrity and evidentiary value.
Why server logs require forensic certification
- Logs are automatically rotated by providers (every 7-30 days typically) and overwritten – without timely certification, attack evidence disappears permanently;
- Log files downloaded without forensic procedure are easily contestable (“could have been modified after download”);
- Provider dashboards show only aggregates (Cloudflare, AWS CloudFront) – granular details (individual requests, IP, User Agent) disappear quickly;
- Without qualified timestamp and chain of custody, logs don’t have full evidentiary value in legal proceedings;
- Professional forensic analysis identifies attack patterns, attacker IPs, temporal sequences that a simple download doesn’t reveal.
Types of certifiable logs
🌐 Web Server Logs
- Apache HTTP Server: access.log, error.log, ssl_access.log, ssl_error.log
- Format: Common Log Format (CLF), Combined Log Format, custom format
- Contains: Client IP, timestamp, HTTP method, requested URL, status code, User-Agent, Referer
- Nginx: access.log, error.log, nginx_error.log
- Upstream logs (if reverse proxy)
- SSL/TLS handshake logs
- Microsoft IIS: W3C Extended Log Format, NCSA Common Log Format, IIS Log Format
- FTP logs if configured
- Failed Request Tracing logs
- LiteSpeed: access.log, error.log (Apache-compatible format)
Forensic utility: Identify attacker IPs, SQL injection attempts, path traversal, brute force on login, web shell upload, bot scraping.
🗄️ Database Logs
- MySQL/MariaDB:
- General Query Log (all executed queries)
- Slow Query Log (suspicious slow queries)
- Error Log (connection errors, syntax errors from injection)
- Binary Log (replication log – useful for audit)
- Audit Plugin logs (MariaDB Audit Plugin)
- PostgreSQL:
- postgresql.log (query log if log_statement configured)
- pg_log (connection logs, errors, queries)
- CSV log format for structured analysis
- MongoDB:
- mongod.log (database operations)
- Audit logs (MongoDB Enterprise)
- Profiler data (slow operations)
- Microsoft SQL Server:
- SQL Server Error Log
- SQL Server Audit logs
- Transaction Log (for recovery forensics)
Forensic utility: Track unauthorized access to sensitive data, successful SQL injections, data exfiltration, privilege escalation attempts.
🔥 Firewall and Security System Logs
- iptables/netfilter (Linux): blocked/accepted connection logs, port scan detection
- pfSense/OPNsense: firewall logs, IDS/IPS alerts (Suricata/Snort), VPN logs
- Cisco ASA/Firepower: connection logs, threat detection, access list hits
- Fortinet FortiGate: traffic logs, threat logs, web filter logs
- Palo Alto Networks: traffic logs, threat logs, URL filtering, wildfire analysis
- Windows Firewall: Windows Firewall with Advanced Security logs
- UFW (Ubuntu): ufw.log with matched rules
Forensic utility: Document DDoS attacks, port scanning, intrusion attempts, blocked traffic from/to suspicious IPs.
☁️ CDN, WAF and Cloud Provider Logs
- Cloudflare:
- HTTP Request Logs (Logpush/Logpull)
- Firewall Events (triggered WAF rules, blocked requests)
- Rate Limiting events
- DDoS attack logs
- Bot Management logs
- AWS CloudFront + WAF:
- CloudFront access logs (S3 bucket)
- AWS WAF logs (matched web ACL rules)
- CloudWatch Logs Insights queries
- Akamai:
- Access logs (DataStream)
- Security events (Kona Site Defender)
- Bot Manager logs
- Google Cloud CDN + Armor:
- Cloud CDN logs (Cloud Logging)
- Cloud Armor security policy logs
- Azure Front Door + WAF:
- Access logs (Azure Monitor)
- WAF logs (matched policy rules)
Forensic utility: Analyze Layer 7 attacks (HTTP flood), SQL injection blocked by WAF, geographic attack patterns, bot traffic.
🖥️ Operating System Logs
- Linux:
- /var/log/auth.log (Debian/Ubuntu): SSH/sudo login attempts
- /var/log/secure (RHEL/CentOS): system authentication
- /var/log/syslog: general system messages
- /var/log/kern.log: kernel messages
- /var/log/messages: system-wide messages
- journalctl (systemd): unified logging
- Windows:
- Security Event Log: login/logout, access control, privilege use
- System Event Log: services, drivers, system errors
- Application Event Log: application events
- PowerShell logs: script execution, command history
Forensic utility: Track unauthorized SSH access, privilege escalation, malware execution, lateral movement.
🔐 Access and Authentication Logs
- SSH: /var/log/auth.log, sshd logs (brute force attempts, successful logins, source IP)
- FTP/SFTP: vsftpd.log, proftpd.log (file upload/download, modifications)
- Hosting control panels:
- cPanel access logs, error logs
- Plesk panel.log, access_log
- DirectAdmin logs
- VPN: OpenVPN logs, WireGuard logs, IPsec logs (connections, disconnections, client IP)
- RDP (Remote Desktop): Windows Security Log Event ID 4624/4625 (login success/failure)
Forensic utility: Identify unauthorized administrative access, credential stuffing attacks, SSH brute force.
📱 Web Application Logs
- PHP error_log: application errors, warnings, fatal errors
- WordPress:
- debug.log (if WP_DEBUG active)
- Security plugin logs (Wordfence, iThemes Security, All In One WP Security)
- Activity logs plugins (WP Activity Log, Simple History)
- Node.js/Express: application logs (console.log, winston, bunyan)
- Python/Django: django.log, gunicorn access/error logs
- Java/Tomcat: catalina.out, localhost_access_log, application logs
- Ruby on Rails: production.log, development.log
Forensic utility: Track application errors exploited by attackers, injection attempts, malicious file uploads.
📊 SIEM and Log Aggregators
- ELK Stack (Elasticsearch, Logstash, Kibana): query results export, saved searches, dashboards
- Splunk: search results export, notable events, dashboards
- Graylog: streams export, search results
- Wazuh: alerts, security events, file integrity monitoring
- OSSEC: HIDS alerts, rootcheck, syscheck logs
Forensic utility: Multi-source event correlation, complete attack timeline, IOC (Indicators of Compromise) identification.
Request a quote
We will immediately provide technical feasibility assessment (log type, volume, format), acquisition method (controlled panel access or exported file processing), execution times and detailed cost estimate.
Forensic analyses performable on logs
🎯 Unauthorized Access Identification
Source IP analysis, temporal patterns, anomalous User-Agents:
- IP Geolocation analysis: access from unauthorized countries (e.g. EU server accessed from Asia/Eastern Europe)
- Anomalous hours: administrative access at 3am when staff normally offline
- User-Agent spoofing: scripts/bots masked as legitimate browsers
- Impossible travel: same account accesses from London 10:00am and Lagos 10:05am
- Login success after brute force: hundreds failed attempts then success with stolen credentials
Output: Attacker IP list with geolocation, access timeline, correlation with compromised credentials.
🔓 Attack Sequence Reconstruction
Complete timeline from first reconnaissance to data exfiltration:
- Phase 1 – Reconnaissance: port scans, directory enumeration (tools: Nmap, dirb, nikto)
- Phase 2 – Initial Access: vulnerability exploit (SQL injection, file upload, RCE)
- Phase 3 – Persistence: web shell installation, backdoor, scheduled task
- Phase 4 – Privilege Escalation: kernel exploit, sudo misconfiguration
- Phase 5 – Lateral Movement: access to other internal network servers
- Phase 6 – Data Exfiltration: database download, sensitive documents
- Phase 7 – Cover Tracks: log deletion, timestamp manipulation
Output: Complete Kill Chain with timestamp each phase, IPs used, commands executed, affected files.
💉 SQL Injection Detection
Identification of attempts and successful SQL injections in logs:
- Pattern matching: SQL keyword search (UNION SELECT, OR 1=1, ‘ OR ‘1’=’1, etc.)
- URL encoding detection: %27, %20, %3D in GET/POST parameters
- Time-based blind SQLi: SLEEP(), WAITFOR DELAY patterns
- Error-based SQLi: responses with MySQL/PostgreSQL error messages
- Database query log correlation: web logs comparison with database query log
Output: Suspicious request list, used injection payloads, possibly extracted data.
🔨 Brute Force Attack Analysis
Documentation of massive access attempts:
- SSH brute force: thousands login attempts from single IP or distributed botnet
- WordPress wp-login.php: user enumeration and password guessing attempts
- FTP brute force: credential scan on port 21
- RDP brute force: repeated Windows Event ID 4625
- Credential stuffing: use of credentials stolen from other breaches
Output: Attempt volumes, source IPs (with ASN/ISP), attempted usernames, any successes.
🌊 DDoS Pattern Recognition
Analysis of volumetric and application attacks:
- Layer 7 HTTP Flood: thousands simultaneous GET/POST requests
- Slowloris attack: partial connections exhausting resources
- UDP Flood: massive UDP traffic (firewall logs)
- SYN Flood: half-open connections (netstat, firewall logs)
- Amplification attacks: DNS/NTP amplification pattern
- Botnet fingerprinting: botnet identification (Mirai, Emotet signature)
Output: Traffic peaks with timestamp, attacker IPs, attack type, consumed bandwidth volume.
🕵️ Insider Threat Investigation
Tracking suspicious employee/administrator activities:
- Off-hours access: admin connected weekend/night without justification
- Massive downloads: unauthorized database backups, company files
- Privilege abuse: access to data not relevant to role
- Data exfiltration: uploads to personal clouds, external FTP transfers
- Log tampering: log deletion/modification attempts
Output: Suspicious activity timeline, accessed/downloaded files, correlation with HR events (resignations, terminations).
🔍 Data Breach Scope Assessment
Determination of what data was compromised:
- Database query analysis: which tables/columns queried by attacker
- File access logs: documents opened/downloaded during intrusion
- Outbound traffic: data volume transferred to external IPs
- PII exposure calculation: how many records with personal data (name, email, password hash) affected
- GDPR breach notification requirement: assessment if 72h notification threshold exceeded
Output: Detailed compromised data report, record count, GDPR/authority notification necessity.
Use cases: when to certify server logs
🚨 Corporate Data Breach
Typical scenario: Company server compromised, customer data database accessed by hacker, need to reconstruct what was stolen for GDPR notification and criminal complaint.
What we certify: Apache/Nginx logs with SQL injection requests, MySQL database logs with attacker-executed queries, SSH auth.log with unauthorized access, complete timeline from initial access to exfiltration, attacker IPs with geolocation, extracted data volume.
Purpose: Criminal complaint for unauthorized access and data theft, GDPR notification to Data Protection Authority within 72h, affected subjects communication, cyber insurance claim.
💼 Ex-Employee Sabotage
Typical scenario: Terminated ex-IT employee still has SSH/FTP server access, deletes critical files, databases, backups for revenge. Company discovers sabotage after days.
What we certify: auth.log with SSH login from ex-employee IP after termination date, FTP logs with massive file deletions, database audit log with DROP TABLE commands, action timeline vs termination date, IP correlation with ex-employee residence.
Purpose: Criminal complaint for computer sabotage, damage compensation claim, disciplinary procedure if still in notice period.
🌐 DDoS Attack Documentation
Typical scenario: E-commerce suffers Layer 7 DDoS attack during Black Friday, site unreachable for hours, estimated sales loss £50,000. Need to prove attack for damage claim.
What we certify: Cloudflare Analytics with traffic peaks, Firewall Events log with millions blocked requests, attack pattern (HTTP flood on /checkout), identified botnet IPs (with ASN), downtime duration, normal vs attack traffic comparison.
Purpose: Compensation claim to hosting provider if SLA violated, complaint if perpetrator identified, business interruption insurance claim.
🔐 GDPR Violation – Unauthorized Personal Data Access
Typical scenario: Marketing employee accesses without authorization HR database with salaries, colleague health data. HR discovers after report, GDPR audit needed.
What we certify: PostgreSQL database audit log with SELECT queries on HR tables from unauthorized user, access timestamps, employee workstation IP, specific viewed data (columns), access frequency (months?), company role correlation (not relevant).
Purpose: Disciplinary procedure, Data Protection Authority notification if breach, GDPR compliance audit Art. 32 (security measures).
⚖️ Court Expert Witness
Typical scenario: Civil lawsuit between company A and B, dispute over when contract file modified on shared server. Court-appointed expert requests forensic log analysis.
What we certify: Server web access log with contract file access timestamp, FTP log with file modifications, file system metadata (mtime, ctime, atime), User-Agent and IP who modified, file hash comparison previous versions from backups.
Purpose: Technical expertise for court expert, determination who and when modified disputed file, evidentiary value for judgment.
Regulatory framework: compliance and legal obligations
🇪🇺 GDPR – Regulation (EU) 2016/679
Art. 32 – Security of processing: Controllers must implement appropriate technical and organizational measures, including ability to ensure confidentiality, integrity, availability and resilience of systems. Logging and monitoring are considered essential measures.
Art. 33 – Personal data breach notification: In case of data breach, controller must notify supervisory authority within 72 hours. To determine breach scope is fundamental log analysis: what data accessed, how many records, when.
Art. 5(1)(f) – Integrity and confidentiality: Obligation to process data in manner ensuring appropriate security, including protection against unauthorized processing. Logs are primary tool to detect unauthorized access.
EDPB Guidelines: European Data Protection Board recommends log retention for appropriate period (typically 6-12 months) to enable security incident investigations.
🛡️ NIS2 Directive (EU) 2022/2555
The NIS2 Directive (Network and Information Security) imposes strict cybersecurity obligations on essential and important entities.
Art. 21 – Cybersecurity obligations: Entities must adopt technical measures to manage incidents, including:
- Incident handling: ability to detect, analyze and respond to incidents;
- Business continuity: crisis management and disaster recovery;
- Supply chain security: supplier monitoring;
- Log management: recording relevant security events.
Art. 23 – Incident notification: Obligation to notify significant incidents within 24 hours (early warning) and 72 hours (incident report). Log analysis fundamental to determine if incident is “significant”.
Penalties: Up to €10 million or 2% global annual turnover (essential entities), up to €7 million or 1.4% turnover (important entities).
🔒 ISO/IEC 27001:2022 – Information Security Management
Annex A Control 8.15 – Logging: “Logs recording activities, exceptions, errors and security-relevant events shall be produced, stored, protected and analyzed.”
Specific requirements:
- Logs must include: user ID, timestamp, event type, outcome (success/failure), event source
- Logs must be protected against unauthorized alterations
- Appropriate retention period for investigations and compliance
- Regular log review to identify anomalous activities
ISO 27001 Audit: During certification audit, auditors always verify that logging is implemented and functional. Log certification demonstrates compliance.
📋 International technical standards
- ISO/IEC 27037:2012 – Guidelines for identification, collection, acquisition and preservation of digital evidence
- NIST SP 800-92 – Guide to Computer Security Log Management (log management, analysis, retention)
- RFC 5424 – Syslog Protocol (log format standard)
- RFC 3161 and ETSI EN 319 422 – Qualified timestamp standards
- PCI DSS Requirement 10 – Track and monitor all access to network resources and cardholder data
- HIPAA Security Rule § 164.312(b) – Audit controls (US healthcare)
- SOC 2 Type II – Logging and monitoring requirements for service organizations
Operational modes: server log certification
Certification process
Mode 1 – Client-exported log file processing (recommended):
- Client exports logs: access to own panels/servers, log export in native format (.log, .txt, .csv, .json, .gz)
- Secure transfer: upload via SFTP/our secure portal, or temporary encrypted cloud sharing
- Receipt and integrity verification: SHA-256 hash calculation of received files, format and readability verification
- Forensic acquisition:
- Bit-by-bit copy original files
- SHA-256 hash calculation for each file
- Qualified eIDAS timestamp on original files
- Working copy creation for analysis (originals untouched)
- Parsing and normalization:
- Log parsing (Apache, Nginx, JSON, CSV format, etc.)
- Timestamp normalization (timezone conversion → UTC)
- Field extraction: IP, timestamp, User-Agent, URL, status code, etc.
- Import into forensic database for analysis
- Forensic analysis:
- IP analysis: geolocation (MaxMind GeoIP2), WHOIS/ASN, reputation (AbuseIPDB)
- Pattern detection: brute force, SQL injection, path traversal, bot traffic
- Timeline reconstruction: attack event sequence
- Anomaly detection: statistical outliers (traffic spikes, unusual times)
- Correlation: web logs + database logs + system logs
- Technical report:
- Executive summary
- Analysis methodology
- Detailed findings with evidence
- Graphical event timeline
- IOC list (attacker IPs, malicious User-Agents, exploit URLs)
- Remediation recommendations
Mode 2 – Controlled client panel access:
When logs not easily exportable or client prefers our direct access:
- Digital mandate: client signs mandate authorizing read-only panel access (cPanel, Plesk, Cloudflare, AWS Console)
- VPN/IP whitelisting access: connection from certified fixed IP, possible client VPN
- Direct acquisition: certified dashboard screenshots, log export from interfaces, API calls for Cloudflare/AWS
- Screen recording (optional): video recording of acquisition operations for chain of custody
- Logout and revocation: at end, client revokes temporary access
What you receive after certification: the complete forensic package
- Certified original log files:
- Exact copy of provided/acquired log files
- SHA-256 hash of each file for integrity verification
- Qualified eIDAS timestamp on each file
- Metadata: size, creation date, format
- Technical Forensic Analysis Report (100-200+ pages typically):
- Executive Summary (2-3 pages): synthesis for non-technical management/legal
- Methodology: tools used, procedures followed, standards applied
- Attack Timeline: event chronology from first scan to exfiltration
- IP Analysis: attacker IP table with geolocation, ASN, ISP, reputation score
- Attack Patterns: SQL injection attempts, brute force stats, DDoS pattern
- Data Breach Scope (if applicable): what data compromised, how many records
- IOC List: Indicators of Compromise (IP, domain, malicious file hashes, User-Agent)
- Evidence Screenshots: key log entry screenshots with highlighting
- Graphics and Visualizations: traffic graphs, attack heatmap, geographic IP map
- Normalized Forensic Database (optional):
- Logs imported into SQLite/PostgreSQL for subsequent queries
- Normalized schema with indexes for performance
- Example SQL queries for custom analyses
- Interactive Visual Timeline (optional):
- Interactive HTML with event timeline
- Filters by IP, timestamp, event type
- Drill-down on specific events
- Machine-Readable IOC Feed:
- CSV/JSON with attacker IPs, malicious domains, file hashes
- Importable into firewall, IDS/IPS, SIEM
- STIX/TAXII format if requested (threat intelligence standard)
- FEDIS Declaration: The FEDIS makes certification admissible in UK/EU courts;
- Chain of Custody Documentation:
- Who acquired logs, when, how
- File custody during analysis
- List of persons with file access
- Expert Witness Statement (optional, for court):
- Sworn statement on methodology and findings
- Forensic expert CV (24 years experience)
- Availability for court testimony
- Qualified eIDAS electronic signature on final report;
- International qualified timestamp (optional): for extra-EU validity (USA, etc.).
- Certified original log files:
GDPR compliance and data processing
System logs contain personal data (IP addresses, in some cases username, email). We manage everything in full compliance with GDPR (EU 2016/679):
- Legal basis: Legitimate interest (Art. 6, par. 1, let. f GDPR) for establishment, exercise or defense of a right (computer attack investigation, criminal complaint, regulatory compliance)
- Data minimization: we acquire only logs strictly necessary for requested investigation
- Purpose limitation: data used exclusively for forensic analysis and purposes indicated by client
- Technical security: logs stored in encrypted environment, limited access, operation traceability
- Limited retention: logs retained only for time necessary investigation + legal obligations (typically 1-2 years), then secure deletion
- Pseudonymization: when possible, attacker IPs pseudonymized in public reports (full IPs only in confidential annexes)
- Data subject rights: attacker IPs are personal data but GDPR rights limited when processing for crime establishment (Art. 23 GDPR)
When to activate server log certification
- if your server has been compromised and you need to reconstruct attack sequence for complaint;
- if you suffered data breach and must determine scope for GDPR notification;
- if you suspect unauthorized access by employees/ex-employees;
- if you suffered DDoS attack and want to document it for damage claim;
- if you must demonstrate GDPR Art. 32 compliance (security measures) or NIS2;
- if you need ISO 27001 audit and must prove functioning logging;
- if you have PCI DSS audit and must document Requirement 10 (log management);
- if there’s legal dispute over file modifications/access and need court expertise;
- if you must investigate insider threat (employee downloads data before resignation);
- if your logs are about to be rotated/deleted by provider (act quickly!);
- if you need expert witness for technical court testimony;
- if you must file cyber insurance claim with solid attack documentation.
Request a quote
We will immediately provide feasibility assessment (log type, volume, format, investigation objectives), technical acquisition method (file export vs controlled access), execution times and detailed cost estimate. URGENT 24-48h intervention available for critical cases with logs at imminent deletion risk.
Important technical note: Forensic analysis quality depends on granularity and completeness of available logs. In quote phase we evaluate free whether available logs are sufficient for requested objectives. We always recommend immediately exporting logs as soon as incident suspected – providers rotate/delete logs after 7-30 days typically. For very large volumes (>100GB logs) we can agree specific transfer and processing methods. Express service 24-48h for emergencies (ongoing attacks, logs at deletion risk, GDPR notification deadlines).
- Authenticating Webpage Evidence in Court
- Unauthorized Account Access Certification with IP | FEDIS
- Accounting Records Certification for Injunctions
- Analysis and Certification of Fake Photos and Videos
- Certified Web Permanence of Online Content
- Click Fraud & Web Traffic Certification
- Crypto Scam Evidence Certification (Web, Wallet & On-Chain)
- Copyright Infringement Certification
- Deepfake and Manipulated Content Certification | Legal Validity
- DM Instagram chat certification
- Defamation & Threats Certification
- Email Account Breach Certification
- Give legal value to the messages sent to your customers via whatsapp
- Google Location History Certification
- Google Takeout Certification
- Certificación de Robo de Imagen
- Identity Theft Certification
- Legal Web Page Certification | Certified Web Content
- Legal Warning Certification
- Microsoft Account Export Certification
- Messenger chat certification
- Online Email Certification
- OnlyFans Content Certification
- Original Authorship Certification
- Past Web Content Existence Certification (Archived & Non-Archived Evidence)
- Social Network Content Certification
- Patreon Content Certification
- Reviews Certification
- Server Logs Certification
- Trademark & Unfair Competition Certification
- Unpaid Overtime Certification (GPS Data)
- Web Page Certification with text and images
- Web Page Certification with Video
- Web Page Certification with File
- Whatsapp and Telegram Chat Certification
