Skip to content
FRP-080 Fraud & Financial Crime

Could closing an application destroy useful evidence?

Yes. Closing an application can remove or alter evidence that exists only in its current live state.

Why this matters

The dangerous assumption is that closing an application simply tidies the screen. It may save files, discard drafts, end sessions, clear temporary data or change timestamps.

What to record and do

An open chat may contain unsent text. A browser may hold an authenticated session. A remote desktop may be the only live route to another system.

A command window may show activity that is not fully recorded elsewhere.

Before closing anything, record the application name, window title, account, visible content, prompts and surrounding screen.

Do not close applications simply to reveal what is underneath.

If the application appears frozen or unresponsive, do not force it to close without specialist advice.

Closing may also trigger synchronisation, logout or security alerts.

Where immediate operational necessity requires closure, record why, what was closed and what changed.

Capture any save, logout or warning prompt before responding.

Document whether data was saved, discarded or became inaccessible.

Closing a browser can remove temporary tabs, authenticated sessions and content held only in cache. Closing a security tool may stop monitoring or destroy a useful view of current activity. Record whether the application is local, cloud-based or remotely hosted before any decision.

Do not assume that reopening the application will restore the same content, credentials or connection state.

Record who authorised the closure and whether any replacement record or specialist capture was obtained first.

Operational takeaway

Assume closing an application may destroy live, temporary or session evidence, and preserve the visible state before any closure decision.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.