When a breach occurs, the problem is rarely a lack of security data. The harder problem is turning all of that into one defensible answer:
What actually happened, how far did the attacker get, what data was affected, and what needs to be contained?
That is the real test of a data breach investigation.
For organizations evaluating Fidelis, this is also where the value of combining Fidelis Network®, Fidelis Endpoint®, Fidelis Deception®, and Fidelis Elevate® becomes clearer.
Fidelis Elevate® brings those capabilities together under a common investigation and management layer rather than treating network, endpoint, and deception as separate security silos. Investigators can correlate network activity, endpoint behavior, deceptive-asset interactions, threat intelligence, and other security context as the same incident develops.
The analyst should not have to export an IP address from one console, find the corresponding endpoint in another, and manually reconstruct whether both events belong to the same attack.
What Does Fidelis Help Establish During a Data Breach Investigation?
A breach investigation eventually has to answer five questions:
How did the attacker gain a foothold?
What happened on the compromised system?
Where did the attacker move next?
Was sensitive data accessed, staged, or transferred?
How far does the compromise extend, and has it actually been contained?
No single telemetry source answers all five equally well. That is why Fidelis’ role in a data breach response is better understood as an evidence chain rather than as a collection of product features.
Investigation questionFidelis evidence that helps answer it
What executed?Endpoint process, file, script, persistence, memory, and user activity Where did it communicate?Network sessions, protocols, destinations, metadata, and behavioral contextWhere did the attacker move?East-west network activity combined with endpoint and deception evidenceWas the behavior likely unauthorized?Interactions with deceptive credentials, breadcrumbs, decoys, or fake assetsWhat data may have been affected?Endpoint file activity combined with network transfer and DLP/content context where availableHow broad is the incident?Retrospective searches across network and endpoint evidenceWhat should be contained?The systems, identities, processes, and communication paths supported by the reconstructed evidence
The important part is what happens between those questions. One finding becomes the pivot for the next. Here is what that can look like.
Post-Breach Detection
and Response
The Shift to Detection and Response
Rise of Deception Defense
Detect Post-breaches 9x Faster
Follow the Evidence: A Data Breach Investigation with Fidelis
Imagine the first indication of compromise is not ransomware or a high-severity malware alert. Instead, Fidelis Deception detects the use of a deceptive credential from an employee workstation.
That signal starts the investigation. It does not finish it.
1. Fidelis Deception Gives the Analyst a High-Confidence Starting Point
Security teams investigate ambiguous behavior every day. Interaction with a deceptive asset is different.
Fidelis Deception goes beyond placing static decoys in the environment. It can profile and classify assets, map the cyber terrain, understand communication patterns, and use that context to help determine where deception should be deployed. Decoys can then be automatically created, deployed, tested, and updated as the environment changes.
The deception layer can include realistic systems and services, breadcrumbs on real endpoints, fake credentials, deceptive data, and Active Directory lures such as fake accounts and groups. Those breadcrumbs can appear in places attackers commonly search, including browser password stores, registry entries, cached shares, files, and credential artifacts leading unauthorized users toward controlled decoys instead of production systems.
For the investigator, that provides more than another detection. A deception interaction can expose the source system, credential being used, reconnaissance behavior, and the attacker’s intended next step before the analyst has reconstructed the entire attack chain.
That does not mean the deception event alone proves a data breach. It tells the analyst where to look next with far greater confidence. In this case, the investigation looks at finding out what happened on the workstation before that credential was used.
The investigation pivots to Fidelis Endpoint®.
2. Fidelis Endpoint Establishes What Happened on the Host
The analyst now examines activity surrounding the deception event. Perhaps the endpoint evidence shows a sequence similar to:
A single suspicious authentication has now become an execution story.
Fidelis Endpoint continuously records process and child-process activity, file creation and modification, registry activity, DNS queries, network connections, loaded DLLs, and other behavioral telemetry that investigators can query retrospectively. First-time-seen executables and scripts can also be collected centrally, helping preserve evidence even if an attacker later deletes the original file.
Once an endpoint becomes part of the investigation, the analyst can go deeper without immediately reimaging the system. Fidelis Endpoint supports remote live response, forensic file collection, full disk imaging, process dumps, memory acquisition, and live memory analysis. Investigators can inspect volatile evidence such as running processes, network sockets, injected DLLs, open handles, and other memory artifacts that may disappear after shutdown or reboot.
The endpoint can then be isolated while retaining communication with Fidelis and designated investigator systems, allowing forensic work and remediation to continue without leaving the compromised machine connected to the wider environment.
But endpoint evidence still tells only part of the story. The analyst now knows what happened on the workstation. The investigation needs to continue to answer where the attacker went next.
That requires network evidence.
3. Fidelis Network Reconstructs What Happened Before and After the Alert
The analyst takes the suspicious destination, host, username, or timestamp identified during the endpoint investigation and pivots into Fidelis Network.
Now the timeline can expand in both directions.
The investigation uncovers:
DNS activity before the suspicious connection
communication with previously unseen external infrastructure
downloads or earlier sessions associated with the compromised system
SMB connections to internal file servers
RDP sessions involving other endpoints
LDAP or Kerberos activity associated with discovery or credential use
transfers between internal systems
communication with systems that have no endpoint agent installed
The endpoint shows that a process made a connection. The network helps establish where that connection went, what surrounded it, and what other systems became part of the attack path.
Fidelis Network’s Deep Session Inspection® is designed to reassemble and analyze network sessions and extract rich metadata rather than relying only on basic flow information.
That depth is important during forensic reconstruction. Fidelis Network can extract more than 300 attributes from network sessions, including protocol, application, file, certificate, TLS, timing, and communication context. Rather than limiting an analyst to source IP, destination IP, port, and byte counts, the investigation has additional evidence to pivot on.
Deep Session Inspection also supports analysis across north-south and east-west traffic and can derive behavioral and metadata context from encrypted sessions without requiring every session to be decrypted. Where policy permits deeper inspection, selective SSL decryption can add further content visibility.
Fidelis Network also combines NDR with capabilities such as network forensics, threat intelligence, sandboxing, and DLP. That means an analyst can move from detecting suspicious communications to examining the session, investigating transferred files or content, and determining whether the same behavior exists elsewhere.
4. Fidelis Helps the Analyst Look Back Before the Initial Detection
This is particularly important because the alert that starts an investigation is rarely guaranteed to represent the beginning of the intrusion.
The attacker may have entered earlier. The suspicious infrastructure may have appeared before anyone knew it was malicious. The analyst therefore needs to search backward.
For investigations that need to reach farther back, Fidelis serves as the optional storage and analytics component of Fidelis Network. It stores the rich metadata generated from network sessions and can support more than 360 days of searchable metadata, depending on deployment and configuration.
That allows a newly discovered IOC, domain, certificate characteristic, protocol attribute, file indicator, or other session artifact to be applied retrospectively. An indicator that means nothing on Monday may become critical threat intelligence three weeks later; investigators can search historical metadata to determine whether it appeared before the original detection.
5. Fidelis Network Helps Follow the Attack Where EDR Cannot
Suppose the investigation now reveals this path:
Network evidence helps bridge the gap between workstation, server, and user. It is important because real environments contain systems where endpoint agents may be impractical, unsupported, absent, or intentionally excluded.
Fidelis Network gives investigators another way to track the attack path across those systems.
This is a more practical reason to combine NDR and EDR than simply saying the organization gains “360-degree visibility.”
6. Fidelis Endpoint, Network, and Deception Reconstruct Lateral Movement Together
Now imagine the attacker uses the compromised credential to begin exploring the environment.
Network evidence identifies SMB or RDP activity toward another system.
Endpoint evidence shows which process or user initiated it.
Then Fidelis Deception records interaction with a decoy server or deceptive credential.
Individually, each signal provides useful context.
Together, they become much harder to dismiss.
For example:
Endpoint: PowerShell launches under the compromised user’s session.
Network: The workstation begins making unusual east-west connections.
Deception: The same source interacts with a resource that has no legitimate business purpose.
The analyst can now connect execution, movement, and attacker behavior.
This is where deception adds something particularly useful to a breach investigation.
Endpoint and network evidence help show what happened.
Deception can help highlight which activity represents purposeful exploration of an attack path that a normal user or system should not be taking.
Fidelis Elevate brings these different evidence sources together so the analyst can investigate the incident as one attack rather than three unrelated alerts.
7. The Investigation Now Moves from Compromise to Data Impact
At this point, many security investigations would already have enough information to declare an incident.
A data breach investigation cannot stop there.
Security teams, incident responders, legal teams, and business leaders eventually need to know: What data was affected?
Suppose Fidelis Endpoint shows that the attacker accessed a sensitive directory and created an archive. A few minutes later, Fidelis Network identifies an unusual outbound transfer from the same server. Now the investigation has two important pieces of evidence:
Endpoint evidence: Sensitive files may have been collected or staged.
Network evidence: Data subsequently moved toward an external destination.
Where traffic visibility and inspection policies allow, Fidelis Network’s DLP and content-aware capabilities can provide additional context for investigating the information involved.
This is where the combination of NDR and network DLP becomes particularly relevant to a breach investigation. Detecting an unusual outbound connection establishes suspicious communication. DLP and content inspection can help determine whether the session involved sensitive information and what policy or data classification it matched.
The investigation can therefore correlate three different forms of evidence:
Endpoint: Were sensitive files opened, copied, compressed, or staged?
Network: Where did the resulting communication go and how did the session behave?
DLP/ content evidence: Did the transferred material match sensitive-data policies or other content criteria?
That is a materially different investigation outcome from knowing only that a large transfer occurred. For breach-notification, legal, compliance, and executive-response decisions, the question is ultimately not just whether an attacker connected out it is what evidence exists about the data involved.
Evidence that customer information, intellectual property, financial data, or regulated information was accessed or transferred changes the response. This is one of the reasons network evidence is particularly relevant to this use case.
A breach investigation does not end when malicious behavior has been identified. It has to establish data scope as far as the available evidence permits.
8. Every New Finding Becomes a Hunt Pivot Across Fidelis
The investigation now contains several indicators:
a suspicious domain
an external IP address
a deceptive credential
a process name
a hash
an internal account
a lateral-movement destination
perhaps a particular protocol or behavioral pattern
The next question is obvious:
Where else have we seen any of these?
This is where retrospective hunting changes the scope of the investigation.
A newly discovered domain can be searched across previous network activity. A process or endpoint indicator can be hunted across endpoint telemetry. A compromised account can be investigated across associated systems and network activity. A deception interaction can be checked against other related activity.
One finding may reveal another compromised system. That system may reveal another account. The account may reveal a second attack path.
A practical data breach investigation procedure therefore does not move in a neat straight line. It behaves more like:
That loop continues until newly discovered evidence stops materially expanding the incident.
This is how the investigation begins to establish a defensible blast radius.
9. Fidelis Helps Contain the Breach Based on Evidence, Not Just the First Alert
Suppose the investigation establishes the following sequence:
Initial workstation compromised
Credential accessed
Internal server reached
Privileged identity used
Sensitive repository accessed
Archive created
Outbound transfer observed
Fidelis Endpoint can also turn those investigative findings into direct response actions. Built-in and customizable response scripts can collect forensic artifacts, terminate processes, isolate endpoints, remove files, modify registry entries, and perform other remediation actions. Fidelis documents more than 100 response scripts across investigative, forensic, and destructive response categories.
Playbooks can chain several actions around a validated detection for example, isolating the endpoint, collecting volatile forensic evidence, checking indicators against threat intelligence, and notifying the appropriate team. Importantly, isolation does not have to end the investigation: the affected host can remain accessible to Fidelis and authorized investigator systems while lateral communication to the rest of the corporate environment is restricted.
This closes an important gap between data breach investigation and mitigation. The evidence used to establish scope can directly inform what gets isolated, collected, blocked, or remediated next.
What About a Cloud Data Breach Investigation?
The same evidence problem becomes even more pronounced in hybrid environments.
A cloud data breach investigation may cross:
employee endpoints
cloud workloads
identities
API credentials
virtual networks
SaaS applications
containers
on-premises systems
The attacker does not respect those boundaries, so the investigation cannot treat each environment as an unrelated case.
Fidelis extends the same investigation model into hybrid environments rather than treating cloud activity as an isolated evidence stream. Fidelis Network can inspect traffic across internal, perimeter, and cloud network segments where the necessary traffic visibility is available. Fidelis Endpoint can continue monitoring supported cloud workloads, while Fidelis Deception can place cloud-specific lures such as fake credentials, API keys, buckets, and other deceptive assets across AWS, Azure, Kubernetes, and hybrid environments.
This becomes useful when an intrusion begins on an employee endpoint but later moves through cloud identities or workloads. An analyst may be able to connect the endpoint process that initiated the activity with the relevant network communication and then use a cloud deception interaction to understand what the attacker attempted to access next.
Why Fidelis Elevate Matters When the Evidence Comes from Different Layers
Fidelis Elevate combines Fidelis Network, Fidelis Endpoint, Fidelis Deception, Active Directory protection, investigation, and response capabilities under a broader XDR architecture.
That provides several practical advantages during a breach:
Cross-domain context: Network, endpoint, deception, and identity findings can be investigated as related activity rather than separate alerts.
Retrospective investigation: New indicators can be used to revisit previously collected evidence.
Active Directory context: Credential abuse and AD-related attack activity can be investigated alongside endpoint and network behavior.
Open architecture: Fidelis supports integrations with third-party security technologies, which matters for enterprises that are not replacing their entire SIEM, SOAR, endpoint, or security stack at once.
Response from the investigation: Evidence can progress into endpoint containment, forensic collection, hunting, and remediation instead of ending as another correlated alert.
Identify and neutralize threats faster
Gain full visibility across your attack surface
Automate security operations for efficiency
For a buyer, this is the real distinction between collecting telemetry and having an investigation architecture.
Conclusion
The objective of a breach investigation is not to prove that the platform can find something malicious.
It is to establish enough connected evidence to explain what happened and what did not.
From First Signal to Defensible Breach Scope
A data breach investigation succeeds when the organization can reconstruct enough of the attack to make defensible decisions. The result is not simply more alerts in one interface.
It is the ability to start with one suspicious signal and keep following the evidence until the team can answer the questions that matter.
Frequently Asked Questions
How does Fidelis help investigate a data breach?
Fidelis helps investigators connect endpoint, network, and deception evidence around the same incident.
endpoint telemetry can establish what executed on a system,network evidence can reconstruct communications and lateral movement,deception can expose suspicious interactions with decoys or deceptive credentials
These findings can then be used to expand the investigation, determine scope, investigate data impact, and guide containment.
How do you investigate a data breach with Fidelis?
A typical investigation may begin with a network, endpoint, or deception signal. The analyst uses that evidence to identify the affected host or identity, examines endpoint activity, reconstructs related network communications, investigates lateral movement, searches historical telemetry for newly discovered indicators, examines potential data access or transfer, and then contains systems based on the reconstructed attack path.
How does Fidelis Network support a network security breach investigation?
Fidelis Network provides session and metadata context that can help investigators
reconstruct external and east-west communications,examine protocol activity,search historical network behavior,identify communications involving unmanaged assets,investigate suspicious data movement.
This complements endpoint evidence that explains what occurred on individual hosts.
Why use Fidelis Deception during data breach investigations?
Fidelis Deception uses decoys, breadcrumbs, deceptive credentials, and other lures to expose suspicious behavior. Because legitimate users typically have little reason to interact with these resources, a deception event can provide a high-confidence starting point or additional evidence during an investigation. It should be correlated with endpoint, network, identity, and data evidence when determining overall breach scope.
What should security teams look for in a data breach investigation platform?
Look for the ability to correlate evidence across multiple security layers, investigate historical activity, follow attacks across managed and unmanaged systems, collect forensic evidence, investigate data movement, search newly discovered indicators across the environment, and take response actions without losing investigative context.
The post Inside a Data Breach Investigation with Fidelis: Connecting Network, Endpoint, and Deception Evidence appeared first on Fidelis Security.
No Responses