VORANT. Threat Intelligence Sign in Get the full feed

NCSC urges forensic observability in network devices

routine threat infrastructuretechnology

NCSC guidance calls on vendors to build supported logging and forensic capabilities into firewalls and VPN gateways so defenders don't need reverse engineering or zero-days to investigate compromise.

The NCSC has published a blog reinforcing 2025 guidance on digital forensics and protective monitoring specifications for network device manufacturers, highlighting that firewalls, VPN gateways, and other edge appliances remain frequent targets for sophisticated threat actors yet often lack built-in support for post-compromise investigation. The core issue: defenders investigating a compromised network device frequently must rely on improvised techniques, reverse engineering, or even discovering and exploiting vulnerabilities themselves to determine what happened — meaning defenders can have fewer tools available than attackers who compromised the device in the first place.

The article outlines 'forensic observability' as the combination of telemetry, logging, configuration state visibility, memory/disk forensic collection capability, and software transparency (e.g., version info, SBOMs) that vendors should build in natively. NCSC is working with international partners on a reference architecture for this capability and cites Sophos's Pacific Rim campaign response as an industry example where extending detection/response to firewall devices materially reduced customer harm. The piece addresses three misconceptions — that observability aids attackers, that customers dislike transparency, and that it's too hard to implement — and closes with calls to action: vendors should build this in from the design phase, and buyers should demand it as a standard evaluation criterion for edge devices.

This is a policy/guidance piece rather than a report of active exploitation or a specific vulnerability, but it is directly relevant to SOC and IR teams' procurement and incident-readiness planning for firewalls, VPN gateways, and other perimeter appliances, given that such devices remain a preferred target class for both criminal and state-linked intrusion sets due to weak native forensic support.

Mentioned in this report

Campaigns Pacific Rim

Source reporting: https://www.ncsc.gov.uk/blogs/making-forensic-observability-the-norm-for-network-devices

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free