What should be preserved immediately?¶
Start with the evidence that is both useful and at risk of disappearing.
You are not trying to copy the whole environment before anybody does anything. You are trying to protect the material that may be lost through normal retention, shutdown, isolation, revocation or recovery.
Think about what may disappear first¶
Depending on the incident, that may include:
- active sessions;
- running processes;
- volatile memory;
- current network connections;
- temporary files;
- endpoint telemetry;
- authentication and identity logs;
- cloud and email audit records;
- firewall, proxy or DNS logs;
- original malicious files, links or pages; and
- live account or provider state.
What evidence may disappear quickly? explains why these sources can be time-sensitive.
Preserve the response record as well¶
The incident response will change things.
Password resets, account revocation, isolation, shutdown, quarantine and rebuilding can all alter the evidence.
So preserve the response chronology too:
Those actions help explain why later logs, sessions or connections look different.
Prioritise rather than collecting blindly¶
A useful order is:
- evidence that may vanish quickly;
- evidence that directly answers the incident question;
- evidence that response activity is about to alter;
- records needed to explain what responders did.
Record how collection happened¶
For every important preservation action, keep:
- source;
- collector;
- time and time zone;
- method;
- scope;
- filters or exclusions;
- any changes caused by collection.
The practical point is: preserve the evidence most likely to disappear or be changed by response activity, and preserve the response itself as part of the incident history.