Skip to content
Skip to main content
First Response & Preservation Technical Explainer

What should be preserved about current network connections?

Capture the complete connection view, its source system and timing before sorting, refreshing or containment changes this short-lived state.

Describe both ends and the route

Record source and destination addresses, ports, protocol, state, interface and associated process or service. Preserve hostnames, VPN details, remote-access indicators, session IDs and start or last-active times where available. Note whether a connection is listening, pending, established or closed and whether a proxy, gateway, load balancer, VPN or cloud service mediates it.

Include the displaying tool, filters, date and time zone. A host table covers only what that system can observe and may omit brief or encrypted activity.

Correlate rather than identify prematurely

An address can represent shared infrastructure, translation, a provider edge, proxy or compromised device. Preserve matching firewall, proxy, cloud and provider logs where relevant. A connection is a timed technical link, not proof of the human controlling it.

Do not terminate unfamiliar traffic without assessing active harm and dependencies. If a connection disappears, record when and what action preceded the change; absence after containment does not show it never existed.

Key takeaway

Preserve connection endpoints, state, route, process and timing as a transient snapshot, then correlate it with wider logs before using it for attribution.

Reference: FRP-194First Response & Preservation