Could recovery overwrite or destroy evidence?¶
Yes. Recovery can overwrite, delete or obscure important evidence if it begins before preservation is complete.
Avoid this assumption: Rebuilding, restoring or cleaning systems affects only malicious material. It may remove logs, malware artefacts, deleted files, memory evidence, configuration changes and traces of attacker access.
Reimaging a device can replace the entire original system.
Restoring a backup may overwrite later files and timestamps.
Resetting accounts may revoke sessions and alter security history.
Patching, antivirus cleaning and configuration changes can remove or quarantine evidence.
Before recovery, identify what evidential questions remain and which systems may answer them.
Preserve relevant devices, logs, cloud records, alerts, audit trails, sessions and response notes.
Record the original system state, date, time, configuration and known compromise.
Where the original system cannot be retained, obtain specialist advice on proportionate acquisition before alteration.
Document every recovery tool, account, script, backup, image and configuration used.
Record files or logs deleted, quarantined, replaced or made inaccessible.
Preserve recovery reports and change records.
Do not rely on a cleaned system as the sole evidence of what happened before remediation.
Where urgent restoration is necessary for safety or critical service, record why preservation was limited and what evidence may have been lost.
Record whether a forensic image, native export, provider preservation or other substitute was obtained before the original system was changed.
Record that decision clearly.
Operational takeaway¶
Treat recovery as a destructive evidential process, and preserve the systems, logs and incident context needed before rebuilding, restoring, cleaning or reconnecting anything.