Skip to content
Skip to main content
First Response & Preservation Technical Explainer

What should be recorded about network connectivity?

Record every visible route by which the system may communicate - wired, wireless, mobile, virtual or remote - before isolation, movement or disconnection changes it.

Connectivity is rarely a single on-or-off state

A device may use Ethernet, Wi-Fi, mobile data, Bluetooth, a VPN, tethering and remote desktop at the same time. Background services can synchronise or receive commands while the display appears inactive, and a disconnected device may reconnect automatically when moved or restarted.

Capture network icons, displayed names, cables and the wider equipment layout. Preserve visible IP addresses, hostnames, network names, remote-session indicators, connected users and security alerts exactly, with the observation time and source.

Avoid opening settings merely to find more detail. That can trigger discovery, reconnection or configuration changes. Provider, router or specialist records may later supply the underlying information more safely.

Isolation trades one risk for another

Disconnection can limit remote deletion or continuing compromise, but it may end a session, stop monitoring, interrupt business services or lose active connection evidence. One cable on a server or network appliance may affect many systems.

Before isolating, define the threat, record current connections and consider operational dependencies. If action is necessary, identify who performed it, the exact method and what immediately changed. The recorded starting point allows later logs to be aligned with the intervention.

Key takeaway

Preserve visible connection routes and identifiers before isolation because the same connectivity may support both valuable evidence and continuing risk.

Reference: FRP-017First Response & Preservation