Skip to content
Skip to main content
First Response & Preservation Operational Explainer

What should be preserved after containment?

Preserve the changed state and every responder-created record needed to compare it with the pre-containment baseline.

Capture the immediate result

Record the exact time each device, identity, interface or service was contained. Capture post-action screens, alerts, sessions, connections, users and service availability. Preserve firewall or configuration changes, isolation records, process termination, account-security events and provider confirmations.

Identify connections that ended or survived, new routes, inaccessible data and unexpected failures. Record failed logins, reconnect attempts, deletion, new accounts or movement to other systems without assuming every later event is an attacker response.

Keep response evidence separate

Preserve incident logs, central monitoring, cloud audit records, workarounds, service restoration and account transfers. Label before-and-after captures and do not overwrite original exports with later versions. The distinction allows analysts to identify what containment created, removed or obscured.

Review isolated systems for remaining volatile evidence and specialist-acquisition needs. Absence of new alerts does not prove removal of the threat; partial or failed containment and uncertainty about resulting changes should be recorded directly.

Key takeaway

Preserve a clearly time-labelled post-containment state and response trail so changes, losses, failures and possible reactions can be compared reliably with the original incident.

Reference: FRP-198First Response & Preservation