Skip to content
Skip to main content
First Response & Preservation Technical Explainer

Could closing an application destroy useful evidence?

Yes.

Closing an application can save or discard work, end authenticated sessions, remove temporary state and change the evidence available later.

The practical rule
Assume live application state may not come back once closed.

What can be lost?

Examples include:

  • unsent chat text;
  • temporary browser tabs;
  • session cookies;
  • active credentials;
  • command history;
  • live remote desktops;
  • unsaved documents;
  • transient prompts; and
  • monitoring state.
Application openLive session and temporary state visibleMay expose content, credentials or remote access.
Application closedState may be goneReopening may create a different session or no session at all.

Do not close something just to see underneath

Move from observation to intervention only for a defined reason.

Before closure, record:

  • application;
  • account;
  • visible content;
  • prompts;
  • whether it is local/cloud/remote;
  • time; and
  • reason for the change.

Capture prompts before choosing

Save / Discard / Logout / End Session prompts can themselves explain what state exists.

Record them before selecting an option.

If live state is important, seek specialist capture first.

The practical point is: closing software is a destructive change to the live environment. Preserve the application state before making that decision.

Reference: FRP-080First Response & Preservation