Could recovery overwrite or destroy evidence?¶
Yes. Rebuilding, restoring, cleaning and reconnecting can remove or obscure evidence as well as repair the service, so proportionate preservation must precede recovery.
Recovery writes a new system state¶
Reimaging replaces the original installation; backup restoration can overwrite later files and timestamps; account resets revoke sessions and change security history. Patching, antivirus action and configuration changes may delete or quarantine malware, logs and traces of access. Memory evidence and unsaved state disappear on shutdown.
Before alteration, define the unanswered evidential questions and the devices, provider records, alerts, audit trails and responder notes that can answer them. Record original configuration, timing and known symptoms. Seek specialist acquisition where the source cannot be retained and its evidential value justifies capture.
Preserve the recovery footprint¶
Document every image, backup, tool, script, account and configuration used. Record files or logs removed, quarantined, replaced or made inaccessible, and retain recovery reports and change records separately from the incident evidence.
Critical safety or service needs may limit preservation. In that case, record the urgency, substitute obtained - such as an image, export or provider preservation - and the evidence likely lost. A cleaned system is evidence of recovery, not a complete record of the earlier compromise.
Key takeaway
Treat recovery as an evidence-changing process, preserving the sources needed first and recording every replacement, deletion and configuration change that creates the restored state.