
Figure 1:
Process of systematic literature review
Table 1:
Digital Forensics Roles and Forensic Potential in Energy Infrastructure
| Role of Digital Forensics | Forensic Potential |
|---|---|
| Incident Detection and Analysis | Through log monitoring, monitoring system behaviour and network traffic, anomalies in SCADA/ICS and Smart Grid systems are identified. Forensics analysis which is protocol-aware (which means that unlike the classic digital forensics approach, this method enables investigators to investigate the operational meaning of transmitted messages within the SCADA and ICS environments) enables more reliable detection of anomalies and enhances interoperability with intrusion detection systems (IDS) (Akkad et al., 2023; Alelyani, Kumar G R, 2018; Carcano et al., 2011; Irfan Ahmed, 2012; Kilpatrick et al., 2008, 2006; Kleinmann, Wool, 2014; Mason, Zhou, 2021; Nelufule et al., 2024). |
| Evidence Collection and Preservation | Acquisition of digital data (PLC code, ladder logic, RTU data, and network traces) is enabled securely and without disrupting operations. When digital evidence is collected, it is crucial to maintain the integrity of the collected evidence by preserving the chain of custody using cryptographic hashing, and SCADA-specific data collection plans (Fabro, 2008; Irfan Ahmed, 2012; Senthivel et al., 2017; Van Der Knijff, 2014). |
| Attribution and Accountability | Digital forensics enables the reconstruction of the timeline, steps and actions of the attacker, using PLC forensics, live analysis of memory, and creating an isolated virtual environment in order to safely execute and observe potentially malicious code (sandboxing). Digital forensics in energy infrastructure also enables the attribution and accountability of cyberattacks to the actual attacker or group of attackers. (Eden et al., 2016, 2015; Kamlofsky, Romero, 2022; Maglaras et al., 2019; Mittal, 2015). |
| Forensic Readiness | Integrating forensics readiness models into SCADA systems can minimize digital evidence loss, reduce the mean time to response (MTTR), and strengthen organizational resilience against cyberattacks. Forensic readiness models include following elements: the process of identification of potential sources of digital evidence (SCADA logs, PLC memory, network packets, authentication servers); defining a process of evidence collection which ensures integrity through hashing and timestamping; and developing adequate incident response procedures (Eden et al., 2015; Irfan Ahmed, 2012; Slay, Elena Sitnikova, 2009; Madan Raja et al., 2024; Senthivel et al., 2017; Van Der Knijff, 2014). |
| Incident Response and Recovery | Forensics can guide system recovery by tracking malware spread in real time, changes to the PLC code, and volatile memory. Live forensics of SCADA systems can enable safe analysis while the systems remain operational (Jeffries, 2022; Kamlofsky, Romero, 2022; Mason, Zhou, 2021). |
| Policy, Regulation, and Training Support | Digital forensics helps in enhancing compliance with standards (NERC CIP, NIS2, ISA-99, IEC 62443) and in developing forensic incident response models for strengthening national cyber strategies. The education and training of staff is a crucial part of equipping the energy sector to be able to cope with cyberattacks (Bozhyk et al., 2025; Cusack, Mahmoud, 2018; Eden et al., 2016, 2015; Ene, Savu, 2023). |
Table 2:
Attack Scenarios and Forensic Findings
| Scenario | Examples of Forensic Finds |
|---|---|
| 1. Reconnaissance/Scanning Attack | The logs record the attacker's IP address, targeted protocols, and connection attempts. Scanning is the first step of cyber-terrorism; forensics documents the attempt and enables attribution (Kilpatrick et al., 2008, 2006; Spyridopoulos et al., 2013). |
| 2. Unauthorized Parameter Change (Sabotage) | In this type of cyberattack, the logs can be investigated because they capture an unauthorized WRITE command and the time when the attack occurred. Analysis of the logs can reveal the exact moment and command of the cyberattack (Onyiego, Elisha Abade, 2020; Yau, 2015). |
| 3. Malware Injection | Forensics investigation in this case can enable the early detection of attacks (even when these attacks do not succeed) by investigating the ‘unknown’ or ‘invalid’ command which was registered in the logs after the attack (Iqbal et al., 2019; Kawoosa, Prashar, 2021; Mason, Zhou, 2021; Saeed et al., 2024). |
| 4. Denial of Service (DoS) | The logs reveal sudden spikes in requests and anomalies in traffic. Digital forensics techniques can distinguish between normal and abnormal activity, helping to uncover DoS attacks (Carcano et al., 2011; Yang et al., 2014). |
| 5. Insider Threat | The logs registers repeated login attempts, the use of a default password, and subsequent activity. Cyber-terrorism can also come from the inside; forensic techniques provide the only evidentiary trail of insider actions (Eden et al., 2015; Van Der Knijff, 2014). |
Table 3:
Case study: Major Cyberattacks on Energy Infrastructure – Forensic Potential
| Case | Digital Forensic Potential |
|---|---|
| Stuxnet (2010) |
|
| Triton/Trisis (2017) |
|
| Ukraine Power Grid (2015–2016) |
|
| Colonial Pipeline (2021) |
|