Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What should be preserved immediately?

Start with the evidence that is both useful and at risk of disappearing.

You are not trying to copy the whole environment before anybody does anything. You are trying to protect the material that may be lost through normal retention, shutdown, isolation, revocation or recovery.

Think about what may disappear first

Depending on the incident, that may include:

  • active sessions;
  • running processes;
  • volatile memory;
  • current network connections;
  • temporary files;
  • endpoint telemetry;
  • authentication and identity logs;
  • cloud and email audit records;
  • firewall, proxy or DNS logs;
  • original malicious files, links or pages; and
  • live account or provider state.

What evidence may disappear quickly? explains why these sources can be time-sensitive.

Preserve the response record as well

The incident response will change things.

Password resets, account revocation, isolation, shutdown, quarantine and rebuilding can all alter the evidence.

So preserve the response chronology too:

Example response chronology
06:42 · staff report file disruption06:47 · endpoint state captured06:51 · FILE-03 isolated06:54 · session SES-4C18 revoked07:02 · password reset authorised

Those actions help explain why later logs, sessions or connections look different.

Prioritise rather than collecting blindly

A useful order is:

  1. evidence that may vanish quickly;
  2. evidence that directly answers the incident question;
  3. evidence that response activity is about to alter;
  4. records needed to explain what responders did.
Volatile stateMemory, sessions, processesMay disappear through shutdown or revocation.
Short retentionCloud, identity, network logsMay roll over or expire.
Original materialFiles, URLs, pages, ransom notesPreserve the source item, not only screenshots.
Response historyActions and decisionsExplains later changes in the evidence.

Record how collection happened

For every important preservation action, keep:

  • source;
  • collector;
  • time and time zone;
  • method;
  • scope;
  • filters or exclusions;
  • any changes caused by collection.

The practical point is: preserve the evidence most likely to disappear or be changed by response activity, and preserve the response itself as part of the incident history.

Reference: CIM-010Cyber Incidents & Offender Methods