When should a live-system specialist take over?¶
A live-system specialist should take over when the next action may alter volatile evidence, affect critical services or require technical judgement beyond ordinary first response.
Why this matters¶
The dangerous assumption is that a competent investigator can safely continue as long as the system is visible and accessible. Live systems may contain memory evidence, active sessions, remote users, encryption keys, malware and business-critical processes.
What to record and do¶
Specialist takeover is particularly important where the system is a server, virtual environment, cloud console, network appliance or active incident platform.
Escalate where power, isolation, memory capture, remote access or containment decisions are uncertain.
Seek immediate support where continued operation risks serious harm, but shutdown or disconnection could destroy evidence or interrupt essential services.
Before handover, record the original state, visible applications, accounts, network connections, power, time and any changes already made.
Provide a concise operational briefing. Explain what the system is, how it was found, what is visible, what risk is active and what decision is needed.
Do not reduce the briefing to “the computer is live”. The specialist needs context.
Record who took control, when, what advice was given and which actions followed.
If emergency action is required before takeover, use the least destructive effective measure and document why waiting was not possible.
Specialist takeover should also be considered where legal authority, organisational ownership or third-party control is unclear. Technical access does not answer who may authorise changes, and a live specialist may need to coordinate with legal, provider or system-owner contacts.
Operational takeaway¶
Hand over when live-system decisions require specialist capture, containment or service knowledge, and provide a clear record of the state, risk and actions already taken.