Skip to content
Skip to main content
First Response & Preservation Technical Explainer

Could containment affect timestamps and timelines?

Yes. Response actions create new timestamps, interrupt clocks and logging, and can make later records appear out of sequence unless the original time context is preserved.

Containment changes temporal evidence

Credential changes create login and audit events; file access can update metadata; restart resets uptime; and disconnection may stop clock synchronisation or central log delivery. Cloud records can show provider receipt rather than user action and may use UTC while a device displays local time.

Before action, record displayed system time, time zone, clock source and any observed difference from a trusted reference. Preserve timestamps in their interface and record each response step against a trusted time. Do not adjust an incorrect clock merely to make systems agree.

Build a qualified chronology

Note isolation, restart, reconnection, daylight-saving changes, virtual-machine drift and provider delay. Identify gaps caused by interruption or rotation and label responder-generated events.

Where exact order is unsupported, use ranges and explain uncertainty rather than forcing records into a precise sequence. The aim is to normalise times analytically while retaining the original values and settings from every source.

Key takeaway

Preserve original clocks, zones and responder times because containment can generate events and gaps that must be corrected analytically, not by changing the source records.

Reference: FRP-200First Response & Preservation