What should be preserved before destructive activity is contained?¶
Preserve high-value volatile and short-retention evidence where this does not prolong avoidable harm. Disconnection or power-off can stop destruction while removing memory, sessions, keys, processes and live network state.
Capture the live control picture¶
Depending on urgency and specialist support, preserve memory, processes, users, connections, commands, security alerts, affected files, wipe or encryption activity and management-platform jobs. Export identity, cloud, provider and security records early because local destruction may not affect them.
Those external sources may become the best account, session and command evidence after a device is wiped.
Coordinate preservation and containment¶
Operational safety comes first. Parallel teams may collect live state while blocking credentials, isolating storage or disabling management access. Record the exact sequence because each action changes evidence under collection.
If immediate action prevents capture, document who authorised it, what was lost and which alternative records survive. Preservation is not a reason to allow continuing destruction.
Key takeaway
Capture proportionate live and provider evidence while containing harm, documenting the precise sequence and every evidential consequence.