What evidence may be volatile during an active incident?¶
During an active incident, some of the most useful evidence may exist only briefly and change from moment to moment.
Avoid this assumption: Everything important will remain in logs or on disk after the incident is contained. Live systems may hold temporary evidence that disappears on shutdown, restart, logout or disconnection.
Volatile evidence may include running processes, active network connections, logged-in sessions, memory-resident data, encryption keys, command windows, remote-access activity and temporary credentials.
Security consoles may show alerts, live detections, quarantines, blocked actions and investigation timelines that later change or expire.
Routers, firewalls and network appliances may hold connection tables, DHCP leases, VPN sessions and temporary logs.
Cloud platforms may show current collaborators, active sessions, audit events, sharing state and changing permissions.
Messaging systems may contain disappearing content, unsent drafts, read status and live presence information.
Record the affected system, account, time, time zone, page, filters and visible state.
Do not restart, clear, acknowledge, log out or disconnect automatically.
Seek specialist support quickly where memory, network traffic, malware, remote access or critical infrastructure is involved.
Where immediate harm requires action, preserve the most significant visible state first where possible and record what could not be captured.
Do not overstate completeness. Volatile evidence is a changing snapshot and may require correlation with provider, device and organisational records.
Preserve any indication that logs are rotating, sessions expiring or content synchronising.
Operational takeaway¶
Identify and preserve live sessions, processes, connections, alerts and temporary account state before containment changes them, while prioritising urgent safety and service protection.