Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What should not be altered?

Avoid changing a live incident source casually.

Restarting, deleting, resetting, revoking, uninstalling or rebuilding can all destroy evidence or change the story you are trying to reconstruct.

That does not mean “never touch anything”. It means understand what the action will change before you do it where circumstances allow.

Ordinary fixes can remove useful evidence

Examples include:

Action Evidence it may affect
Restart Memory, processes, active sessions and connections
Delete/quarantine file File contents, metadata, location and execution context
Reset password Existing authentication state and later account behaviour
Revoke sessions/tokens Active-session evidence and continuity
Uninstall software Configuration, logs and local artefacts
Rebuild machine Large parts of the local evidence set

Even opening files, following links or browsing a compromised system can create fresh events.

Sometimes change is necessary

If harm is continuing, leaving a system untouched may be worse than altering it.

For example, you may need to:

  • isolate a host;
  • revoke an account;
  • stop a malicious process;
  • disable a service;
  • take a safety-critical system offline.

The right question is not “will this preserve everything?”

It is:

What do we need to change now, what can we safely preserve first, and how will we record the effect?

HarmWhat happens if we wait?People, systems, money, data or services may remain exposed.
EvidenceWhat will the action change?Sessions, memory, files, logs or configuration.
ActionWhat must be done?Contain, isolate, revoke or recover.
RecordWho did what and when?Preserve the decision and technical effect.

Make the intervention reproducible

Record:

  • who authorised it;
  • who carried it out;
  • exact time;
  • source state before the change where feasible;
  • the action taken;
  • why it was necessary;
  • what evidence was known to be affected.

How should continuing harm and urgency be assessed? helps with that balancing decision.

The practical point is: avoid unplanned changes, not necessary ones. If action is needed, preserve what you reasonably can and make the intervention part of the evidence record.

Reference: CIM-011Cyber Incidents & Offender Methods