What should be recorded when containment changes the evidence?¶
Record every containment action that may alter a system, account, session or record as part of the incident timeline. Response activity changes what investigators can observe and can otherwise be mistaken for offender activity - or for the offender stopping voluntarily.
Containment and evidence preservation are connected operational decisions, not separate histories.
Keep a contemporaneous response log¶
For each material action, record:
- what was done and for what purpose;
- who authorised and performed it;
- the exact time and time basis;
- affected systems, accounts or services;
- evidence preserved beforehand;
- expected and observed effects; and
- known or possible evidence loss.
Relevant actions include isolating devices, terminating sessions, resetting passwords, revoking tokens, blocking infrastructure, disabling accounts, rotating keys, stopping services, deleting files and rebuilding systems. Retain ticket and communication references that connect the decision to its authority and context.
Where several teams act concurrently, use a shared time reference and consolidate their logs so one team's change can be matched to another team's observation.
Containment can create evidence¶
Blocked reconnect attempts, failed token use and a switch to another account or host can reveal access that remained active and how the offender reacted. Preserve those events rather than treating containment only as a source of loss.
Staged containment helps show which action changed which later behaviour. If activity disappears after a specific token is revoked, that sequence may be informative, but it should still be reported as an observation rather than proof of the person controlling the token.
Key takeaway
Treat containment as an evidential event: record its authority, timing, scope and effects so responder changes, offender reactions and later absence of activity can be distinguished.