How should preservation requests be prioritised?¶
Preservation requests should be prioritised by volatility, retention period, evidential value and the risk that the account or data will change.
Evidential caution: that every source can be requested later.
What this means¶
High-priority records may include:
short-retention authentication logs;
active session data;
cloud audit events;
message or object metadata;
provider abuse records;
remote-access logs;
dynamic IP assignment;
temporary accounts;
deleted content;
transaction or payment records.
which provider holds the data;
how long it may retain it;
what precise identifier is required;
whether the account is active;
whether containment may trigger deletion or rotation;
what local evidence supports the request.
Preservation should not be confused with disclosure.
The immediate objective may be to stop loss while the appropriate legal process is completed.
Equally, do not send broad requests without stable identifiers or a clear scope.
Preservation priorities should be reviewed as the incident develops. A newly identified account, wallet, object or infrastructure service may become more important than the sources first known. Update the preservation plan rather than treating the initial list as fixed. The operational takeaway is:
Prioritise provider records that are short-lived, unique and central to attribution or sequence, and preserve them before containment, deletion or retention removes them.
================================================================================
What to check or do next¶
- Investigators should identify:
- Do not delay preservation because every investigative question has not yet been resolved.
Evidential limits¶
It may not be available.
Prioritisation should also consider replaceability. A local copy of a ransom note may be preserved elsewhere, while a short-lived provider session or dynamic address assignment may be unique. Focus first on records that cannot be reconstructed later from another source.