Skip to content
Skip to main content
First Response & Preservation Technical Explainer

Could recovery overwrite or destroy evidence?

Yes. Rebuilding, restoring, cleaning and reconnecting can remove or obscure evidence as well as repair the service, so proportionate preservation must precede recovery.

Recovery writes a new system state

Reimaging replaces the original installation; backup restoration can overwrite later files and timestamps; account resets revoke sessions and change security history. Patching, antivirus action and configuration changes may delete or quarantine malware, logs and traces of access. Memory evidence and unsaved state disappear on shutdown.

Before alteration, define the unanswered evidential questions and the devices, provider records, alerts, audit trails and responder notes that can answer them. Record original configuration, timing and known symptoms. Seek specialist acquisition where the source cannot be retained and its evidential value justifies capture.

Preserve the recovery footprint

Document every image, backup, tool, script, account and configuration used. Record files or logs removed, quarantined, replaced or made inaccessible, and retain recovery reports and change records separately from the incident evidence.

Critical safety or service needs may limit preservation. In that case, record the urgency, substitute obtained - such as an image, export or provider preservation - and the evidence likely lost. A cleaned system is evidence of recovery, not a complete record of the earlier compromise.

Key takeaway

Treat recovery as an evidence-changing process, preserving the sources needed first and recording every replacement, deletion and configuration change that creates the restored state.

Reference: FRP-202First Response & Preservation