What should be preserved before destructive activity is contained?¶
The practical answer¶
Before containing destructive activity, preserve volatile evidence, active sessions and the records most likely to be altered by shutdown or remediation.
The key evidential caution¶
The dangerous assumption is that immediate disconnection or power-off is always evidentially harmless.
It may stop harm, but it can also remove:
Key points¶
- memory
- running processes
- active sessions
- encryption keys
- command channels
- unsaved logs
- network state
- evidence of the controlling account
Investigators should consider preserving:
- memory
- process and service lists
- logged-in users
- network connections
- command history
- security alerts
- cloud and provider logs
- affected files
- deletion or wipe commands
- ransom or threat messages
- management-platform activity
Operational safety and harm prevention remain the priority.
Where immediate containment is necessary, record what was done, by whom, when and what evidence could not be captured.
Evidential limits¶
Do not allow preservation activity to prolong avoidable destruction.
Specialist support may be required to balance live evidence against continuing harm.
Where destructive activity is active, preservation and containment may need to occur in parallel. One team may capture live state while another blocks credentials, isolates storage or disables management access. Record the sequence because containment can alter the very evidence being collected.
Provider-held identity, cloud and security records should be preserved early because local destruction may not affect them. They may provide the best surviving account, session and command evidence after a device or server has been wiped.
This may materially preserve attribution.
Operational takeaway¶
Capture high-value live evidence where proportionate, then document containment precisely and preserve provider, account and system records before they change or expire.