What should not be altered?¶
Avoid changing a live incident source casually.
Restarting, deleting, resetting, revoking, uninstalling or rebuilding can all destroy evidence or change the story you are trying to reconstruct.
That does not mean “never touch anything”. It means understand what the action will change before you do it where circumstances allow.
Ordinary fixes can remove useful evidence¶
Examples include:
| Action | Evidence it may affect |
|---|---|
| Restart | Memory, processes, active sessions and connections |
| Delete/quarantine file | File contents, metadata, location and execution context |
| Reset password | Existing authentication state and later account behaviour |
| Revoke sessions/tokens | Active-session evidence and continuity |
| Uninstall software | Configuration, logs and local artefacts |
| Rebuild machine | Large parts of the local evidence set |
Even opening files, following links or browsing a compromised system can create fresh events.
Sometimes change is necessary¶
If harm is continuing, leaving a system untouched may be worse than altering it.
For example, you may need to:
- isolate a host;
- revoke an account;
- stop a malicious process;
- disable a service;
- take a safety-critical system offline.
The right question is not “will this preserve everything?”
It is:
What do we need to change now, what can we safely preserve first, and how will we record the effect?
Make the intervention reproducible¶
Record:
- who authorised it;
- who carried it out;
- exact time;
- source state before the change where feasible;
- the action taken;
- why it was necessary;
- what evidence was known to be affected.
How should continuing harm and urgency be assessed? helps with that balancing decision.
The practical point is: avoid unplanned changes, not necessary ones. If action is needed, preserve what you reasonably can and make the intervention part of the evidence record.