What should be preserved about active sessions and processes?¶
Preserve enough detail to identify each live session or process, place it in time and show its relationship to users, parent activity and remote systems before termination changes it.
Capture the technical relationships¶
For sessions, record usernames, login times, source addresses, device labels, authentication methods and session IDs. Note whether access is local, remote, administrative, service-based, disconnected or active, including VPN, remote desktop, shell, virtual-machine or container context.
For processes, preserve the name, identifier, parent, user account, start time, executable path, command line, service and status where shown. Record the system, tool, page, displayed time zone and whether activity appears interactive, scheduled, automated or controlled from another host.
Avoid attribution from labels alone¶
Accounts can be shared or compromised and processes can be renamed or launched by other software. These records demonstrate technical activity and relationships, not automatically the responsible person.
Ending a session or process may remove unsaved data, command history, memory evidence and attacker visibility. If active harm requires termination, capture the most useful visible detail first where safe and record the reason, exact time and result. Malware or complex live access calls for incident-response support.
Key takeaway
Preserve session and process identity, lineage, timing and access context before termination, then corroborate those technical associations before drawing conclusions about a person.