I have encountered a live device, account or digital system
Protect people and preserve evidential choices through deliberate, attributable decisions. Action may change evidence, but delay may lose access, dynamic data or an immediate safeguarding opportunity.
Start with what needs doing now
Use this route to assess urgency, authority, volatility, available support and the least intrusive effective action.
Balance safeguarding, evidence change, speed and unavailable specialist support in a bounded real-world decision.
Reference FRP-000Record the starting stateBefore anybody touches anythingFix the device, screen, power, network and handler position before the first interaction.
Reference FRP-006UK decision supportWhen can circumstances justify interaction?Connect urgency, available resources and limited intervention to recognisable UK decision-making and evidence principles.
Reference UK-001Understand the evidence and the offender method
Use this route to understand first-response principles and see the same pressures inside a separate offender operation.
Understand observation, preservation, acquisition, examination and individual accountability.
Reference FRP-001Separate offender exampleDodgy Dave's live betting operationSee changing cloud, messaging and payment evidence handled while specialist support cannot arrive in time.
Reference FRP-212Go directly to the issue you need to resolve
Identify access, memory, sessions, synchronisation and changing records.
Reference FRP-005Decision recordDocument an urgent interventionRecord the objective, authority, options, actor, action and result.
Reference FRP-012AccountabilityRecord investigator-created changesExpose what each person did instead of presenting one vague chronology.
Reference FRP-203ContinuityProtect the audit trailIdentify every handler, transfer, action and resulting state.
Reference FRP-205Browse every First response and preservation guidance page
The complete reference library remains available when you need a narrower question.- A live device, account or digital system may be relevant to my investigation - where do I start?
- What is digital first response?
- What is preservation?
- What is the difference between preservation and acquisition?
- What is the difference between acquisition and examination?
- What is volatile digital evidence?
- What should I record before touching anything?
- What should I photograph or capture first?
- What identifiers should be preserved immediately?
- What questions should I ask the person who found or controls the system?
- When should I avoid interacting with the device or account?
- When should immediate intervention take priority over preservation?
- How should I document an urgent first-response decision?
- When should I stop and seek specialist support?
- Why is the original state important?
- What should be recorded about the screen?
- What should be recorded about power and battery state?
- What should be recorded about network connectivity?
- What should be recorded about logged-in accounts?
- What should be recorded about open applications?
- What should be recorded about notifications?
- What should be recorded about date, time and time zone?
- What should be recorded about connected cables and peripherals?
- What should be recorded about removable storage?
- What should be recorded about nearby devices?
- What should be recorded about visible usernames and account IDs?
- Should I take screenshots or photographs?
- What are the limitations of screenshots and photographs?
- Should I switch a digital device off?
- Should I leave a digital device powered on?
- What evidence may be lost when a device is powered off?
- What risks exist if a device remains powered on?
- Could a powered-on device be remotely wiped?
- Could a device lock if the screen turns off?
- Could encryption become harder to access after power loss?
- Could shutting down create new records?
- Is pulling the power cable the same as shutting down?
- What should I consider with a desktop computer?
- What should I consider with a laptop?
- What should I consider with a server?
- What should I consider with a network appliance?
- What should I consider with a smart or embedded device?
- When should a specialist make the power decision?
- What is device isolation?
- Why might a device need to be isolated?
- Could isolation prevent remote deletion?
- Could isolation cause evidence loss?
- Should I enable flight mode?
- Does flight mode disable every connection?
- Could Wi-Fi reconnect automatically?
- Could Bluetooth remain active?
- Could a device communicate through a cable?
- Could removing a SIM alter the evidence?
- What should I consider with an eSIM after removing a physical SIM?
- Should I disconnect a network cable?
- Could disconnecting a server affect other users or evidence?
- What is a Faraday bag and what can it do?
- What are the limitations of a Faraday bag?
- Could isolation affect location, time or synchronisation records?
- How should an isolation decision be documented?
- What should I do first when I encounter an unlocked phone?
- What should I do first when I encounter a locked phone?
- Should I keep an unlocked phone awake?
- Could interacting with the screen change the evidence?
- Could checking the battery level change the evidence?
- Should I connect a phone to a charger?
- Could charging create a data connection?
- Could a phone receive new messages while being preserved?
- Could a phone synchronise deletions or edits?
- Could biometric access be lost?
- Should I ask the user for the passcode?
- What should be recorded if a passcode is supplied?
- Could repeated unlock attempts cause data loss?
- What should I do with a damaged mobile device?
- What should I do with a wet mobile device?
- When should a mobile-device specialist be contacted immediately?
- What should I do first when I encounter an unlocked computer?
- What should I do first when I encounter a locked computer?
- Could moving the mouse or pressing a key alter the evidence?
- What should I record about open windows and applications?
- Could closing an application destroy useful evidence?
- Could logging out destroy useful evidence?
- Could a live computer contain unsaved data?
- What evidence may exist only in memory?
- What is a live-memory capture?
- Should an investigator attempt a live-memory capture?
- Could remote-access software be active?
- Could another user be connected to the computer?
- Could a virtual machine be running?
- Could a container or remote desktop hold the relevant evidence?
- What should be preserved from a live command window or console?
- When should a computer be isolated from the network?
- When should a live-system specialist take over?
- What should I do when I encounter a logged-in online account?
- What should be preserved from the account before interaction?
- Could navigating the account create new records?
- Could opening a page update the account’s activity history?
- Could logging in from another device alter the evidence?
- Could changing a password alert another user?
- Could changing a password terminate useful sessions?
- Could changing recovery details destroy useful context?
- Should I revoke linked devices or sessions?
- What should be recorded before revoking a session?
- Could account security action cause remote deletion?
- Could securing the account protect a victim from further harm?
- How should preservation and safeguarding be balanced?
- Could an administrator access the account without the user?
- What should be preserved from an account-security page?
- When should a provider or platform specialist be contacted?
- Could opening a message alter the evidence?
- Could opening a message create a read receipt?
- Could opening disappearing content consume it?
- Could a message request change when opened?
- Could reconnecting a messaging device trigger synchronisation?
- Could blocking an account alter the evidence?
- Could leaving or removing someone from a group alter the evidence?
- What should be preserved before blocking or removing access?
- Could opening an attachment create a new record?
- Could opening a link expose the device or investigation?
- What should be preserved from a live messaging conversation?
- When should a messaging specialist take over?
- What should I do when I encounter a live cloud session?
- Could cloud data change while I am viewing it?
- Could another user delete cloud evidence remotely?
- Could logging out remove local cloud data?
- Could reconnecting a device trigger cloud synchronisation?
- Could downloading a cloud file alter audit records?
- Could opening a shared document create a viewing record?
- Could changing sharing permissions alert other users?
- What should be preserved from cloud-sharing settings?
- What should be preserved from cloud version history?
- Could a cloud recycle bin or deleted-items folder be volatile?
- What should be preserved from cloud audit or activity records?
- When should the organisation or cloud provider be contacted?
- When should specialist cloud support be sought?
- What should I do when I encounter a router or network appliance?
- Should I restart a router?
- Could restarting a router destroy useful evidence?
- What should be recorded from a router display or interface?
- What should be preserved about connected devices?
- Could disconnecting a network affect several evidential systems?
- What should be preserved from DHCP or connection tables?
- What should be preserved from firewall or security alerts?
- Could logs be lost when network equipment is powered down?
- Could an attacker remain connected to the network?
- When should network isolation be considered?
- When should a network or incident-response specialist take over?
- What should I do when I find a USB storage device?
- Should I plug an unknown USB device into a computer?
- Could connecting removable media alter it?
- Could removable media contain malicious software?
- What should be recorded about removable storage?
- What should I do with a memory card?
- What should I do with an external hard drive?
- What should I do with a hardware security key?
- What should I do with a cryptocurrency hardware wallet?
- What should be recorded about connected printers or scanners?
- Could a peripheral contain its own logs or storage?
- When should removable media be handled only by a specialist?
- What is a provider preservation request?
- What can a preservation request achieve?
- What can a preservation request not achieve?
- When should provider preservation be considered?
- What identifiers should be preserved before contacting a provider?
- Could provider records disappear quickly?
- What should be preserved before an account is deleted?
- What should be preserved before an employee account is disabled?
- Could disabling an organisational account alter other evidence?
- What should an organisation preserve during an incident?
- What is a legal hold or retention hold?
- Does preservation mean the material will automatically be disclosed?
- How should preservation requests and responses be documented?
- When should legal, communications-data or specialist support be sought?
- What should I ask a victim to preserve?
- Should a victim continue using the affected device?
- What should I ask a witness to preserve?
- Should a witness forward messages or files to the investigator?
- Could taking screenshots alter the evidence?
- Should a victim or witness delete harmful content?
- What should be preserved from a victim’s account-security alerts?
- Could account-recovery action destroy useful evidence?
- What should be preserved before a victim changes credentials?
- How should consent and authority be documented?
- Could another household or workplace user control the device?
- When should the original device be retained?
- When may a native export be sufficient?
- When should a specialist acquire the material?
- What should I do during an active cyber incident?
- What evidence may be volatile during an active incident?
- Should compromised systems be disconnected immediately?
- Could immediate disconnection prevent further harm?
- Could immediate disconnection destroy visibility of the attacker?
- What should be recorded before containment?
- What should be preserved about active sessions and processes?
- What should be preserved about current network connections?
- Could containment alert the offender?
- What should be recorded during containment?
- How should containment decisions be justified?
- What should be preserved after containment?
- Could containment create new logs and alerts?
- Could containment affect timestamps and timelines?
- When should recovery begin after containment?
- Could recovery overwrite or destroy evidence?
- How should changes caused by the investigator be recorded?
- How should uncertainty about the original state be reported?
- What is continuity of digital evidence?
- What should be recorded when digital material changes hands?
- What should be recorded about specialist advice?
- How should a decision not to seize or preserve something be documented?
- What are the most common digital first-response mistakes?
- When should a first-response line of enquiry stop?
- What is the overall investigator checklist for first response and preservation?
- When can circumstances justify interaction?
- Dodgy Dave's live betting operation