What should be recorded when containment changes the evidence?¶
Every containment action that may alter systems, accounts, sessions or records should be recorded precisely.
Evidential caution: that response activity is separate from the evidential timeline.
What this means¶
It is not.
Containment may:
terminate sessions;
change passwords;
revoke tokens;
isolate devices;
block domains or addresses;
delete files;
disable accounts;
stop services;
rotate keys;
rebuild systems;
trigger provider alerts;
change timestamps.
what action was taken;
who authorised it;
who performed it;
when;
which system or account was affected;
the purpose;
the expected effect;
the actual effect;
what evidence was preserved first;
what evidence may have been lost.
Likewise, later absence of activity may result from containment rather than the offender stopping voluntarily.
Where several teams act at once, maintain a shared response log with consistent time references.
Containment may also create new evidence. Password resets, token revocation, blocked connections and failed reconnect attempts can show what access remained active. Preserve those resulting events rather than treating containment only as a loss of evidence.
Where containment is staged, preserve which action changed which later observations. Blocking one account may cause the offender to switch identities, while isolating one host may redirect activity elsewhere. Those reactions can be evidentially important.
Also preserve responder communications and ticket references linking each action clearly to its purpose and authority. The operational takeaway is:
Treat containment as part of the incident timeline, and document every evidential change so responder activity is not confused with offender activity.
================================================================================
What to check or do next¶
- Investigators should record:
- Do not attribute responder-created changes to the offender.