Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What should be preserved before terminating a remote session?

Preserve the live identifiers and activity that will disappear when a suspicious remote session ends, where this can be done safely and proportionately. Evidence collection must not create an unacceptable delay in stopping ongoing harm.

Disconnection can remove current connection details, running commands, transfer state, chat, temporary files and memory artefacts. It may also alert the controller. The response therefore needs an explicit balance between evidence, safety and operational continuity.

Preserve first where safe Why it may be volatile
session/operator identifiers may disappear when the connection closes
current source/destination connection live network state may not survive termination
visible commands, transfers and open files transient activity may not be retained elsewhere
relevant running processes / memory state shutdown or process termination can destroy it
provider or platform session record may be short-retention even if held remotely

This is a prioritisation aid, not a reason to delay urgent containment.

Capture the minimum live picture

Depending on urgency and specialist support, record the current screen, time, session and operator identifiers, source connection, active processes, open files, commands, transfers and network connections. Relevant memory or live-response data may preserve code and credentials that will not survive termination.

Provider, gateway and security-platform logs can often be exported without interacting directly with the controller. Obtain them before disabling accounts or changing configuration if time permits. A session recording should be preserved with its metadata, not just as an informal screen capture.

Make containment reproducible

Do not postpone action merely to complete an ideal collection while people, services or sensitive data remain at serious risk. Record who authorised termination, the method and exact time, what was collected, what could not be collected and why.

Afterwards, check other active sessions, tokens, accounts, tools and persistence. Ending one connection does not prove access has ended. Reconnection attempts may produce valuable new account or infrastructure evidence, so ensure monitoring and preservation continue.

Interaction with a live session changes evidence and can provoke the controller. Where the risk or technical consequences are uncertain, specialist advice should shape the collection and termination sequence.

Key takeaway

Capture volatile session and platform evidence when safe, terminate access according to continuing risk, and document the decision and every resulting change.

Reference: CIM-090Cyber Incidents & Offender Methods