Crossâlayer forensic investigation is addressed for Industrial Internet of Things (IIoT) device attacks in Critical Infrastructure (CI) applications. The operational motivation for crossâlayer investigation is provided by the desire to directly correlate bitâlevel network anomaly detection with physical layer (PHY) device connectivity and/or status (normal, defective, attacked, etc.) at the time of attack. The technical motivation for developing crossâlayer techniques is motivated by (a) having considerable capability in place for HigherâLayer Digital Forensic Information exploitationârealâtime network cyberattack and postattack analysis, (b) having considerably less capability in place for LowestâLayer PHY Forensic Information exploitationâthe PHY domain remains largely under exploited, and (c) considering cyberâphysical integration as a means to jointly exploit higherâlayer digital and lowestâlayer PHY forensic information to maximize investigative benefit in IIoT cyber forensics. A delineation of higherâlayer digital and lowestâlayer PHY elements is provided for the standard network Open Systems Interconnection model and the specific Perdue Enterprise Reference Architecture commonly used in IIoT Industrial Control System/Supervisory Control and Data Acquisition applications. A forensics work summary is provided for each delineated area based on selected representative publications and provides the basis for presenting the envisioned crossâlayer forensic investigation.