A forensic report is the most accurate document your security team will ever write about a breach. It names the accounts that moved, the files that left, the channels that carried them, and the dates. It is also a document about something that is already gone.
That is the whole problem with forensics, and it is not a problem with forensics. Forensic data response responds to data that already left. The output is an account of a loss, not a stop on one. The disclosure letter is the deliverable. Why that timing is fixed, and not a tooling gap someone could close with a better parser, is what tells you what a runtime layer has to do instead.
Forensics earns its place after the fact
Forensics answers the questions that arrive once an incident is known. How much left. Whose data. Over what dates. It feeds the legal and regulatory machinery that a breach sets in motion: the notifications, the filings, the litigation hold. It produces evidence that survives a deposition.
None of that is optional. A regulated firm cannot disclose responsibly without an accurate timeline. An insurer will not pay without one. A board cannot rule on a breach it cannot describe. The work is hard, the tools that do it well are worth their cost, and nothing here replaces them.
The limit is the trigger, not the analysis
A forensic investigation begins when someone already knows there was an incident. That knowledge almost never comes from inside the data path. A third party notifies you. A customer finds their records for sale. A regulator asks a pointed question. An extortion note lands in an inbox.
The clock between the first move and the day the organization learns of it runs in weeks and months, not minutes. Breach reports have put dwell time in that range for years, and the worst cases sit at the long end, because nothing about them looked wrong while they ran. So the forensic clock starts on a move that finished long ago. The investigation rebuilds the path. It does not reach back and recall the file. Precise and too late describe the same work, for one reason: it starts after the fact, because the fact is what summons it.
The move forensics finds last
The slowest breaches to discover share one property. Every individual move was permitted.
Picture the case that reaches the forensic team months in. A user with legitimate access reads systems they are authorized to read. The data leaves through a channel built for real work: an approved transfer job, a sanctioned API, a backup route. No policy broke on any single action. No credential was stolen. No malware ran. There is no alert, because nothing tripped a rule.
The pattern across those moves is the breach. The volume is wrong for that identity. The timing is off. The destination is approved; the rate to it is not. Spread the same total across two weeks of small, off-hours transfers and every slice reads as ordinary work. A permission check looks at one event at a time, and the danger lives in the correlation between them.
Forensics does see this pattern. It is often the centerpiece of the post-incident timeline. But it reads the pattern off a completed sequence, which means it reads it after the last byte landed where it should not. The same property that hides the move from permission checks in the moment is what stalls the discovery that calls forensics in the first place.
The third place to stand
There are three places to stand relative to a data move.
Stand before it, with predictive tools that guess which moves will turn dangerous. Fast, wrong often enough to bury a team in false alarms, and still blind to the permitted move, because it looks like everything else.
Stand after it, with forensics. Accurate, evidentiary, working on data that is already gone.
Stand during it. While the data moves, at runtime, on the movement itself. That is the one vantage where the pattern is both visible and still actionable, because the move is forming instead of finished.
Hilt watches data movement at the kernel, metadata only by default, off the path. It runs single-tenant inside your own cloud, on the order of 0.1% of one core and 4 to 8 MB of memory per host, and it never sits inline. It does not read your data to know a pattern is wrong. Metadata is the default vantage; content-aware inspection is there when you ask for it, not the cost of entry. Each move resolves to a probabilistic, source-dependent identity: which user, which job behind it, which destination, and whether this fits what that identity normally does.
When the permitted-but-wrong pattern forms, the deviation shows up across layers at once. The job is unusual for the identity. The read is a bulk pull of high-value paths in a tight window. The volume to an approved destination is out of profile. Any one signal is noise. Together they are a pattern, and a pattern is written as a case, not buried as an alert. When the case warrants it, Hilt responds with host-level network isolation, a quarantine issued from the control plane, never by filtering packets inline.
That is the timing gap, stated plainly. Forensics tells you what left. A runtime layer surfaces the move as it forms, while there is still a host to isolate and a transfer to cut at the network.
What earlier discovery actually changes
The goal is not to retire forensics. After an incident you still need the timeline, the scope, the evidence, the disclosure. Those needs stay, and so do the tools that serve them.
What changes is which incidents reach that stage. The move forensics finds last, permitted channels, legitimate credentials, a pattern that only resolves across many small actions, is the move a runtime layer is built to catch while it is still happening. Close that gap and the forensic team is not obsolete. The forensic timeline just gets shorter, because the most dangerous move was caught forming instead of reconstructed after it completed.
The test for a security leader is one question. If your stack cannot tell you, in time to act, that this identity's data is moving in a way it never has, then the first accurate account of that move will be a forensic one, and it will land after the data is gone.
If that is worth knowing before the disclosure letter, it is a short conversation. The first call runs engineer to engineer, about thirty minutes, on where the collector sits and what it watches.