<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Forensic-Readiness on microsegment.io</title>
    <link>https://microsegment.io/tags/forensic-readiness/</link>
    <description>Recent content in Forensic-Readiness on microsegment.io</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 01 Sep 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://microsegment.io/tags/forensic-readiness/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>When The Network Infrastructure Lies</title>
      <link>https://microsegment.io/post/2026-09-01-when-network-infrastructure-lies/</link>
      <pubDate>Tue, 01 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-09-01-when-network-infrastructure-lies/</guid>
      <description>&lt;p&gt;Most security architectures assume the network will tell the truth.&lt;/p&gt;&#xA;&lt;p&gt;The router reports its configuration. TACACS records who administered it. Syslog preserves what changed. The monitoring platform shows which paths were active. During an incident, those records become the timeline.&lt;/p&gt;&#xA;&lt;p&gt;But what happens when the attacker controls the systems that create the evidence?&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.sygnia.co/blog/fire-ant-evolves-from-hypervisors-to-trusted-infrastructure/&#34;&gt;Sygnia&amp;rsquo;s August 2026 Fire Ant investigation&lt;/a&gt; describes a China-nexus actor compromising Cisco IOS XR routers, TACACS infrastructure, and Linux management hosts. The actor used routers for covert connectivity and traffic collection, intercepted administrative authentication, maintained persistent access, and manipulated logging and command output.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
