What evidence may disappear quickly?¶
Some incident evidence can vanish in minutes. Other records may last days, months or years.
The useful question is:
What exists now that may not exist by the time somebody asks for it later?
Volatile evidence can disappear through normal response¶
Examples include:
- memory;
- running processes;
- active network connections;
- live sessions;
- temporary files;
- tokens;
- current browser state;
- command output;
- transient cloud or application state.
Shutting down, isolating, logging out or rebuilding a system may alter or destroy some of that material.
That does not mean those actions are wrong. It means the evidence risk should be understood before the change where safely possible.
Logs can disappear without anybody deleting them¶
Many logs are kept on rolling retention.
For example:
Do not assume every organisation keeps every log indefinitely.
External evidence can change too¶
Relevant websites, domains, hosted pages, social profiles or cloud resources may be:
- edited;
- deleted;
- suspended;
- moved;
- reconfigured.
If the external state matters, preserve it promptly using the appropriate lawful and technically sound method.
Prioritise by risk of loss and value¶
You do not need to copy everything simply because it exists.
Ask:
- Does this source answer an important question?
- Is it likely to change or disappear?
- Can it be preserved safely?
- What action might destroy or alter it?
- Who is best placed to collect it?
That gives you a sensible preservation order.
Record how preservation happened¶
For anything collected, keep:
- source;
- time and time zone;
- collector;
- method;
- scope;
- any filters;
- any changes caused by collection.
What should be preserved immediately? turns this into a practical priority list.
The practical point is: preserve the useful evidence that is genuinely at risk of loss first. Volatility is about time and system behaviour, not about collecting everything indiscriminately.