The firewall is the choke point that records every inbound/outbound session to the IoT device; its timestamps on the first suspicious connection will most reliably show when the exploit traffic first hit the network. Reviewing those entries pinpoints the initial compromise time before diving into more granular device or segment logs.