What should be preserved before terminating a remote session?¶
Preserve the live identifiers and activity that will disappear when a suspicious remote session ends, where this can be done safely and proportionately. Evidence collection must not create an unacceptable delay in stopping ongoing harm.
Disconnection can remove current connection details, running commands, transfer state, chat, temporary files and memory artefacts. It may also alert the controller. The response therefore needs an explicit balance between evidence, safety and operational continuity.
| Preserve first where safe | Why it may be volatile |
|---|---|
| session/operator identifiers | may disappear when the connection closes |
| current source/destination connection | live network state may not survive termination |
| visible commands, transfers and open files | transient activity may not be retained elsewhere |
| relevant running processes / memory state | shutdown or process termination can destroy it |
| provider or platform session record | may be short-retention even if held remotely |
This is a prioritisation aid, not a reason to delay urgent containment.
Capture the minimum live picture¶
Depending on urgency and specialist support, record the current screen, time, session and operator identifiers, source connection, active processes, open files, commands, transfers and network connections. Relevant memory or live-response data may preserve code and credentials that will not survive termination.
Provider, gateway and security-platform logs can often be exported without interacting directly with the controller. Obtain them before disabling accounts or changing configuration if time permits. A session recording should be preserved with its metadata, not just as an informal screen capture.
Make containment reproducible¶
Do not postpone action merely to complete an ideal collection while people, services or sensitive data remain at serious risk. Record who authorised termination, the method and exact time, what was collected, what could not be collected and why.
Afterwards, check other active sessions, tokens, accounts, tools and persistence. Ending one connection does not prove access has ended. Reconnection attempts may produce valuable new account or infrastructure evidence, so ensure monitoring and preservation continue.
Interaction with a live session changes evidence and can provoke the controller. Where the risk or technical consequences are uncertain, specialist advice should shape the collection and termination sequence.
Key takeaway
Capture volatile session and platform evidence when safe, terminate access according to continuing risk, and document the decision and every resulting change.