What should be preserved about current network connections?¶
Capture the complete connection view, its source system and timing before sorting, refreshing or containment changes this short-lived state.
Describe both ends and the route¶
Record source and destination addresses, ports, protocol, state, interface and associated process or service. Preserve hostnames, VPN details, remote-access indicators, session IDs and start or last-active times where available. Note whether a connection is listening, pending, established or closed and whether a proxy, gateway, load balancer, VPN or cloud service mediates it.
Include the displaying tool, filters, date and time zone. A host table covers only what that system can observe and may omit brief or encrypted activity.
Correlate rather than identify prematurely¶
An address can represent shared infrastructure, translation, a provider edge, proxy or compromised device. Preserve matching firewall, proxy, cloud and provider logs where relevant. A connection is a timed technical link, not proof of the human controlling it.
Do not terminate unfamiliar traffic without assessing active harm and dependencies. If a connection disappears, record when and what action preceded the change; absence after containment does not show it never existed.
Key takeaway
Preserve connection endpoints, state, route, process and timing as a transient snapshot, then correlate it with wider logs before using it for attribution.