What should be preserved before terminating a remote session?¶
Before terminating a suspicious remote session, consider what live evidence may disappear.
Avoid the dangerous assumption¶
The dangerous assumption is that disconnecting immediately is always evidentially neutral.
It may close the safest route to stopping harm, but it can also remove:
- active connection details
- session identifiers
- memory artefacts
- running commands
- operator account information
- file-transfer state
- chat content
- screen activity
- volatile network data
- temporary files.
Where safe and proportionate, preserve:
- the current screen
- session start time
- operator and device identifiers
- source connection details
- active processes
- open files
- network connections
- command history
- files being transferred
- relevant memory or live-response data.
Do not delay containment where people, essential services or sensitive data remain at serious risk.
The decision should balance harm, operational continuity and evidential value.
Specialist support may be required because interacting with the session can alert the controller or alter evidence.
Record who authorised termination, when it occurred, what method was used and what happened afterwards.
Also preserve the remote-access platform’s records before accounts are disabled or settings are changed.
Terminating one session may not remove other access routes. Check active sessions, tokens, accounts, remote tools and persistence.
Where the session cannot be safely observed, preserve the records available from the remote-access platform, network controls and endpoint security before terminating it. Those external records may survive after volatile device evidence disappears.
That decision and any limitations should be documented.
Operational takeaway¶
Capture the live session and connection evidence where feasible, then terminate access in a controlled and documented way proportionate to the continuing risk.