This study aims to analyze the application of a network forensics approach in data breach crime investigations and examine its technical and legal implications. The method used is a qualitative approach through case studies, network log analysis, and a literature review. The research object focuses on the 2021 Microsoft Exchange Server attack case to reconstruct the attack chronology based on network artifacts. The results show that network forensics is effective in systematically identifying attack stages, from initial activity to data exfiltration, and is able to uncover communication patterns and attack methods used by perpetrators. However, challenges arise from the use of anonymity and encryption techniques that complicate the investigation process. From a legal perspective, the analysis results can be used as digital evidence in proving cybercrime in accordance with applicable laws and regulations. This study also emphasizes the importance of forensic readiness in organizations through network monitoring, log management, and the utilization of open information. Thus, network forensics plays a crucial role not only in investigations but also in overall cybersecurity strategies.
Copyrights © 2026