Skip to content
FRP-194 Fraud & Financial Crime

What should be preserved about current network connections?

Current network connections can show which systems are communicating at a particular moment, but they change rapidly.

Avoid this assumption: A single IP address or connection proves who is controlling the activity. Connections may involve shared infrastructure, cloud services, proxies, VPNs, automated processes or compromised accounts.

Record the system, tool, date, time, time zone and visible filters.

Capture source and destination addresses, ports, protocol, connection state, interface and process or service name where shown.

Preserve hostnames, session IDs, VPN details, remote-access indicators and connection start or last-active times.

Record whether the connection is internal, external, local, remote, encrypted, established, listening, pending or closed.

Capture the entire table before sorting, refreshing or selecting an entry.

Do not disconnect the network or terminate a connection solely because it looks unfamiliar.

Where the connection is linked to ongoing harm, seek incident-response or network support and consider the narrowest effective containment measure.

Record whether central firewalls, proxies, cloud platforms or providers may hold corresponding logs.

Be aware that connection tables may be incomplete, short-lived or limited to one system.

If a connection disappears, record the time and any action that may have caused it.

Do not treat the absence of a connection after containment as proof that it never existed.

Record whether the displayed connection is direct or mediated through a proxy, gateway, load balancer, VPN or cloud service.

Operational takeaway

Preserve current network addresses, ports, processes, states and timing before containment, and interpret them as transient technical links requiring correlation and attribution.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.