Skip to content
Skip to main content
First Response & Preservation Operational Explainer

Could disconnecting a server affect other users or evidence?

Yes.

A server may be supporting many users, services and evidence sources at once, so isolating it can change far more than the machine in front of you.

The key point
Map the dependencies before isolating a shared system. A good containment decision protects against harm without accidentally destroying the wider picture.

A single server may support several functions

For example:

IdentityUser authenticationOther systems may depend on it.
ApplicationBusiness serviceUsers may lose access immediately.
LoggingCentral security recordsIsolation may stop incoming evidence.
VirtualisationSeveral virtual machinesOne physical host may contain multiple evidential environments.

A disconnect may therefore terminate:

  • transactions;
  • remote sessions;
  • virtual machines;
  • databases;
  • logs;
  • email;
  • backups; or
  • monitoring.

Containment can still be necessary

If an attacker is actively using the server, isolation may be the right decision.

The question is whether a narrower action could control the risk while preserving more evidence.

Possible targets might include:

  • one account;
  • one service;
  • one network interface;
  • one virtual machine; or
  • one application path.

That normally needs incident-response, system and forensic knowledge.

Record the operational effect

If emergency action is necessary, document:

  • authority;
  • advice available;
  • alternatives considered;
  • chosen action;
  • exact time; and
  • who or what lost service afterwards.
Isolation may achieve

Containment of a live hostile route or continuing compromise.

It may also remove

Shared services, live sessions, central logging and evidence from dependent systems.

The practical point is: server isolation is a shared-system decision. Contain the threat as narrowly as possible and record the wider consequence.

Reference: FRP-055First Response & Preservation