Is the incident still happening?¶
Do not assume an incident has ended just because the first alert was hours ago.
Access may still exist through a live session, token, remote tool, scheduled task, compromised account or malicious process.
The first job is to work out what mechanism could still be active now.
Look for current activity, not just old alerts¶
Useful checks may include:
- active sessions;
- current authentication;
- running processes;
- remote-access tools;
- scheduled tasks;
- continuing file changes;
- ongoing transfers;
- new alerts;
- active forwarding or impersonation;
- continuing operational impact.
A simple current-state view might look like:
That is much more useful than knowing when the incident was first detected.
Silence does not always mean it stopped¶
Telemetry can disappear because:
- the device went offline;
- logging failed;
- a sensor was disabled;
- the activity became intermittent;
- retention rolled over.
So identify the last confirmed event and the visibility you still have.
“No new alerts” is not the same as “nothing is happening”.
Containment and evidence can pull in different directions¶
Stopping a session may destroy volatile state or remove visibility.
Leaving it active may expose more systems, people or data.
The answer is not to prefer evidence over safety.
It is to coordinate the decision and record it.
Record event time, detection time and response time separately¶
The activity may begin at 04:51.
The alert may fire at 05:38.
A person may notice it at 06:42.
Containment may happen at 06:51.
Those times answer different questions.
The practical point is: find the mechanism that may still be active, protect what needs protecting, and record how containment changed both the incident and the evidence.