Preserving Evidence Print

  • 0

The first and most important step.

WHY IT COMES FIRST

Evidence is destroyed by ordinary activity, quickly and permanently.

WHAT DESTROYS IT

Continued use of the system Restarting or shutting down Logging in to examine Running software on it Deleting files Rebuilding Logs rotating and expiring

WHY RESTARTING MATTERS

Information held only in memory is lost, and some systems clear temporary data.

WHAT TO DO FIRST

Stop using the system.

WHAT TO DECIDE

Whether to leave it running or power it off.

WHY IT IS A DECISION

Leaving it running preserves memory and risks continued activity; powering off preserves the disk and loses memory.

WHAT TO CONSIDER

Whether harm is continuing Whether the memory content matters Whether encryption means powering off loses access

WHAT TO ESTABLISH

That the decision is made deliberately and recorded.

WHAT TO PRESERVE

Disk contents Memory, where the capability exists Logs, from the system and from elsewhere Network records Anything with a retention period about to expire

WHY LOGS ELSEWHERE

Logs on the affected system may be altered; logs collected centrally may not.

WHAT TO PRIORITISE

Anything that expires soonest.

WHAT TYPICALLY EXPIRES QUICKLY

Firewall and network records Provider logs Authentication records

WHAT TO DO

Request retention from providers immediately.

WHY IMMEDIATELY

They discard on a schedule and cannot recover afterwards.

WHAT TO RECORD

What was preserved, when, by whom and how.

WHAT TO ESTABLISH

Where preserved material is held, securely.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot