What should I consider with a server?¶
Treat a server as a live shared service. Shutdown, isolation or administrative access can affect many users, destroy volatile evidence and disrupt systems far beyond the physical machine.
Establish operational dependencies first¶
Identify the owner and administrator, services supported and any public-safety, business-continuity or security consequence. Record rack position, labels, displays, storage, network and redundant power connections.
Note warnings, backup power, clustering, shared storage, virtual machines and management consoles already open. Do not log in merely to inspect configuration; authentication and commands add records and can change the system.
A running server may hold memory, active sessions, databases, connection tables and logs that are difficult to reproduce. It may also be participating in continuing compromise or harm.
Coordinate containment and preservation¶
Digital-forensics, incident-response and system-administration roles should normally be engaged quickly. During an active incident, disconnection may contain the threat while removing visibility of the attacker, so record the objective and trade-off.
If urgent action is unavoidable, choose the narrowest effective control and capture advice, decision, operator, time and impact. Never restart or power off a server merely because a powered-off item appears easier to preserve.
Key takeaway
Map a server's shared services and live evidence before intervention, then coordinate any containment through competent operational and forensic support.