What is the overall investigator checklist for first response and preservation?¶
Use a decision sequence: define the evidential question, record the original state, assess volatility and harm, take the least destructive justified action, maintain continuity and stop at the examination boundary.
Understand before changing¶
Identify the device, account, service or system and who found, possessed, used or administered it. Record location, power, screen, clock, connections, cables, peripherals, removable media, open applications, accounts, notifications and identifiers as relevant. Consider what can disappear, change remotely or affect essential services.
Do not automatically switch off, connect, unlock, charge, restart, log out, alter credentials, revoke sessions, open files or attach unknown media. Where immediate protection requires action, preserve what time safely allows and document authority, timing and result.
Preserve the investigation as well as the item¶
Protect provider and organisational records with short retention. Maintain continuity across originals, exports, copies and handovers. Record investigator-created changes, uncertainty, specialist advice and reasoned decisions not to preserve. Keep accounts, addresses and possession separate from personal attribution.
Escalate live, encrypted, damaged, shared, malicious, critical or unfamiliar systems. Stop when preservation and urgent-risk decisions are complete, and hand over a precise question rather than continuing exploratory interaction.
Key takeaway
First response succeeds by preserving a trustworthy starting point and decision trail - not by examining everything available before the right authority and specialist method are in place.