What evidence may be lost when a device is powered off?¶
Powering off a device can remove evidence that exists only while the system is running.
Evidential caution: that all important data is safely stored on the device. Some evidence may exist only in memory, active sessions, temporary storage or unsaved application state.
What this means¶
Potentially volatile evidence includes running processes, active network connections, logged-in sessions, encryption keys, temporary credentials, unsaved documents, clipboard contents, command history, chat state and data held by live applications.
Power loss may also cause the device to lock or re-enable encryption. A device that was accessible while powered on may become much harder or impossible to access afterwards.
Remote desktops, virtual machines, containers and cloud sessions may close. Temporary links between the device and another system may be lost.
A shutdown can also create new records. The operating system may write logs, save settings or close applications in an orderly sequence. Sudden power loss may create different changes or corruption.
Not every powered-off device loses critical evidence, and leaving it on may create other risks. The decision must reflect the device type, current state, likely evidence and operational context.
Before power is removed, record what is visible and seek specialist advice where volatile evidence may matter.
What to check or do next¶
- If the device powers down unexpectedly, document the time, circumstances and resulting change. Do not imply that the original live state was preserved.
Evidential limits¶
Applications may not restore exactly as they appeared. Tabs, prompts, open messages, draft content and live dashboards may disappear or return in a different state.
Operational takeaway
Recognise that power loss may destroy volatile evidence, active access and encryption material, so record the live state and obtain specialist advice before shutdown where practicable.