What should be preserved before persistence is removed?¶
Preserve the mechanism, its configuration and the records connecting creation and use before removal, where continuing risk permits. Deletion can erase the clearest explanation of how access survived.
Capture a reproducible record¶
Retain the stable identifier, files or account, creation and modification history, creator process, trigger, privilege, target command, execution history and linked network or account activity. Prefer native exports and forensic copies to screenshots where available.
Live processes or sessions may require specialist collection. Credentials, tokens and commands should be handled securely; evidential preservation does not justify unnecessary distribution of working access material.
Document containment and wider checks¶
Record who authorised removal, the time, method and resulting changes, including restarts, revocation or provider actions. If urgent risk prevents full collection, document what was lost and which external or historical sources remain.
Removing one route is not proof that access ended. Check linked accounts, tokens, applications, tasks, services, shells and remote tools. Continued monitoring may reveal fallback access, while the response timeline allows later reviewers to distinguish responder activity from offender action.
Key takeaway
Capture the mechanism, creator, trigger and use evidence before removal, then record containment precisely and test for additional footholds.