Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What evidence may disappear quickly?

Some incident evidence can vanish in minutes. Other records may last days, months or years.

The useful question is:

What exists now that may not exist by the time somebody asks for it later?

Volatile evidence can disappear through normal response

Examples include:

  • memory;
  • running processes;
  • active network connections;
  • live sessions;
  • temporary files;
  • tokens;
  • current browser state;
  • command output;
  • transient cloud or application state.

Shutting down, isolating, logging out or rebuilding a system may alter or destroy some of that material.

That does not mean those actions are wrong. It means the evidence risk should be understood before the change where safely possible.

Logs can disappear without anybody deleting them

Many logs are kept on rolling retention.

For example:

Endpoint telemetryMay roll overDepends on product, licence and storage.
Cloud / identity logsMay have short product retentionExport or preservation may be needed early.
Firewall / proxy logsVolume can be very highOlder records may disappear quickly.

Do not assume every organisation keeps every log indefinitely.

External evidence can change too

Relevant websites, domains, hosted pages, social profiles or cloud resources may be:

  • edited;
  • deleted;
  • suspended;
  • moved;
  • reconfigured.

If the external state matters, preserve it promptly using the appropriate lawful and technically sound method.

Prioritise by risk of loss and value

You do not need to copy everything simply because it exists.

Ask:

  1. Does this source answer an important question?
  2. Is it likely to change or disappear?
  3. Can it be preserved safely?
  4. What action might destroy or alter it?
  5. Who is best placed to collect it?

That gives you a sensible preservation order.

Record how preservation happened

For anything collected, keep:

  • source;
  • time and time zone;
  • collector;
  • method;
  • scope;
  • any filters;
  • any changes caused by collection.

What should be preserved immediately? turns this into a practical priority list.

The practical point is: preserve the useful evidence that is genuinely at risk of loss first. Volatility is about time and system behaviour, not about collecting everything indiscriminately.

Reference: CIM-007Cyber Incidents & Offender Methods