Skip to content
CIM-007 Cyber Incidents & Offender Methods

What evidence may disappear quickly?

Some cyber evidence is volatile or retained only briefly.

Evidential caution: that digital evidence will remain available because computers automatically keep everything.

What this means

Active memory may contain running processes, encryption material, network connections, logged-in users and malicious code that may disappear when a system is shut down or restarted.

Active sessions, authentication tokens and temporary files may expire or be destroyed when accounts are reset or sessions are revoked.

Security platforms, cloud services, firewalls, proxies and internet providers may retain records for limited periods. Retention may depend on licence level, configuration, storage limits or whether logging was enabled at the time.

Temporary attacker infrastructure may also vanish. Domains can be changed, servers rebuilt, websites removed and cloud resources deleted.

memory and live-response data;

active remote connections;

current user and administrator sessions;

endpoint and network telemetry;

cloud audit and sign-in logs;

email-security records;

DNS, proxy and firewall logs;

provider-held records;

copies of malicious files, phishing pages and ransom notes;

the organisation’s retention settings.

================================================================================

What to check or do next

  • Ask early about:
  • Do not allow urgency to produce uncontrolled collection. Record who collected the material, from which system, at what time, using what method and whether the action changed the source.

Evidential limits

It does not.

Preservation does not always mean immediately copying everything. It may mean preventing deletion, extending retention, taking a forensic image, exporting logs, recording current state or sending a preservation request.

The most important question is not simply “what evidence exists?” It is “what evidence exists now that may not exist later?”

Operational takeaway

Identify volatile and short-retention evidence at the outset and preserve it before routine response actions, expiry or system changes remove it.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.