Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

Is the incident still happening?

Do not assume an incident has ended just because the first alert was hours ago.

Access may still exist through a live session, token, remote tool, scheduled task, compromised account or malicious process.

The first job is to work out what mechanism could still be active now.

Look for current activity, not just old alerts

Useful checks may include:

  • active sessions;
  • current authentication;
  • running processes;
  • remote-access tools;
  • scheduled tasks;
  • continuing file changes;
  • ongoing transfers;
  • new alerts;
  • active forwarding or impersonation;
  • continuing operational impact.

A simple current-state view might look like:

Example live-incident snapshot
Account: nv-supportSession: SES-4C18 activeEndpoint: FILE-03Remote tool: runningLatest file modification: 10:42:18 UTCStatus: activity continuing

That is much more useful than knowing when the incident was first detected.

Silence does not always mean it stopped

Telemetry can disappear because:

  • the device went offline;
  • logging failed;
  • a sensor was disabled;
  • the activity became intermittent;
  • retention rolled over.

So identify the last confirmed event and the visibility you still have.

“No new alerts” is not the same as “nothing is happening”.

Containment and evidence can pull in different directions

Stopping a session may destroy volatile state or remove visibility.

Leaving it active may expose more systems, people or data.

The answer is not to prefer evidence over safety.

It is to coordinate the decision and record it.

Current harmWhat is still at risk?People, systems, money, data or operations.
Evidence riskWhat may disappear?Memory, sessions, connections or short-lived logs.
ContainmentWhat action is needed?Isolate, revoke, block or otherwise reduce harm.
RecordWhat changed?Time, authority and technical effect of the response.

Record event time, detection time and response time separately

The activity may begin at 04:51.

The alert may fire at 05:38.

A person may notice it at 06:42.

Containment may happen at 06:51.

Those times answer different questions.

The practical point is: find the mechanism that may still be active, protect what needs protecting, and record how containment changed both the incident and the evidence.

Reference: CIM-006Cyber Incidents & Offender Methods