What evidence may be volatile during an active incident?¶
Volatile evidence is live or short-lived state that can disappear through shutdown, restart, logout, disconnection, expiry or continuing system activity.
Volatility exists across layers¶
On a host it may include running processes, memory-resident data, encryption keys, command windows, temporary credentials and logged-in sessions. Networks can hold active connections, address leases, VPN sessions, packet data and buffered logs. Cloud and security consoles may show collaborators, permissions, alerts, quarantines and investigation timelines that change or expire.
Messaging services can add disappearing content, presence and read state. Preserve any warning that logs rotate, sessions expire or synchronisation is in progress. Records written to disk or a central platform can still be incomplete or delayed.
Prioritise by value and loss risk¶
Record the system, account, displayed time zone, page, filters and original state before acknowledging, logging out, restarting or disconnecting. Memory, malware, live traffic and critical infrastructure usually require prompt specialist coordination.
If immediate harm demands containment, capture the most significant accessible state without unsafe delay and document what was missed. A live snapshot is not a complete history; correlate it later with provider, device and organisational records.
Key takeaway
Identify evidence whose state or existence depends on the live system, preserve the highest-value short-lived records first and keep their snapshot limitations explicit.