What should I do first when I encounter an unlocked computer?¶
An unlocked computer may contain live evidence that can disappear through locking, shutdown, remote activity or ordinary use.
Why this matters¶
The dangerous assumption is that an unlocked computer should be searched immediately. Access does not remove the need for lawful authority, proportionality or specialist support.
What to record and do¶
First, record the system as found. Photograph the entire screen, open applications, visible accounts, time, network state, connected devices and the wider physical setup.
Note whether there are remote desktop windows, command prompts, virtual machines, cloud services, active chats, warnings or unsaved documents.
Do not close applications, move windows, browse folders or open messages merely because the system is available.
Avoid touching the keyboard or mouse unless there is a clear reason. Even minor interaction can alter recent activity, wake processes or change the screen.
Consider the risk of automatic locking, sleep, power loss, remote access and continued malicious activity.
Do not disconnect network or power automatically. The correct response depends on what may be lost and what risk remains active.
Where the computer is encrypted, evidentially significant, part of a business system or involved in an active incident, seek specialist advice quickly.
Record every unavoidable interaction and distinguish the original state from all later changes.
Record whether the computer is local, remotely accessed or displaying a virtual machine, because the visible evidence may be held elsewhere. Preserve visible usernames, hostnames, document paths and session indicators before the screen changes.
Operational takeaway¶
Preserve the unlocked computer’s live state before interaction, avoid turning access into examination and obtain specialist support for power, isolation and acquisition decisions.