Skip to content
FRP-090 Fraud & Financial Crime

What should be preserved from a live command window or console?

A live command window or console may show recent instructions, system output and active processes that are not preserved elsewhere in the same form.

Why this matters

The dangerous assumption is that the commands can simply be rerun later. The environment, output, temporary credentials and current system state may change or disappear.

What to record and do

Photograph the entire screen first, including the window title, prompt, username, hostname, path, visible commands, output, time and surrounding applications.

Record whether the console appears local, remote, administrative, cloud-based, inside a virtual machine or connected to a container.

Do not press Enter, arrow keys, Control-C or any other key. The cursor may be sitting on an unfinished command, and one input could execute or terminate activity.

Do not scroll without a clear reason. Scrolling may alter the visible state and lose the original context.

Record any active process, network address, error, warning, file path or account identifier visible.

If the console appears to be controlling malware, infrastructure or a live incident, seek specialist support immediately.

Where interaction is unavoidable to stop serious harm, capture the original state first where possible and document every input and result.

Do not assume the visible username identifies the person who typed the commands.

Preserve any visible command history carefully, but do not assume it is complete or attributable to the current user. A shared account, script, remote operator or automated task may have produced the displayed commands.

Operational takeaway

Preserve the full command-window context before any input, and treat every key press as a potentially significant change to live evidence.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.