What evidence may be lost when a device is powered off?¶
Power loss can remove evidence held only in memory or live applications and can replace an accessible state with a locked, encrypted one.
Live data may not be written to storage¶
Possible losses include running processes, current network connections, authenticated sessions, encryption keys, temporary credentials, unsaved documents, clipboard data and memory-resident command or chat state. Remote desktops, virtual machines, containers and cloud sessions may close.
Tabs, prompts and dashboards may not restore as they appeared. Even when an application reopens, its new display can reflect later synchronisation rather than the earlier state.
Power loss can also require full passcode or recovery authentication and make biometric access unavailable. This changes the opportunity for acquisition without authorising an investigator to search the live device.
Shutdown also creates records¶
An orderly shutdown may save settings, close applications and write system logs. Sudden removal can produce a different trace or corrupt data. Record the chosen method and expected consequences, not merely that the device became “off”.
Not every system holds decisive volatile evidence, and leaving it on creates competing risks. Capture visible state and seek timely specialist advice before power removal where live evidence or encryption access may matter. If shutdown is accidental, record its time and circumstances immediately.
Key takeaway
Power-off decisions must account for memory, sessions, unsaved data and encryption access that may never return in the same form.