98% of software is ripe fucking garbage. Especially if it's a from a commercial environment. In fact, the small, simple, open source tools are the 2% of things that are good.
I second this comment. Logs are usually only good if they are captive and only the overseers have access to them, otherwise unless you catch it real-time you generally won't be able to do any meaningful forensics. Well, unless the suspects are just really stupid which is entirely possible
Correct there always is a trail
No, there's not. Source: am a software developer.
98% of software is ripe fucking garbage. Especially if it's a from a commercial environment. In fact, the small, simple, open source tools are the 2% of things that are good.
I second this comment. Logs are usually only good if they are captive and only the overseers have access to them, otherwise unless you catch it real-time you generally won't be able to do any meaningful forensics. Well, unless the suspects are just really stupid which is entirely possible