Evidence Preservation for Security Investigations
Preserve security evidence with enough context, integrity, and proportionality to support reliable investigation and action.
Preserve context as well as content
Useful evidence answers who observed what, on which system, at what time, and under which limitations. Preserve original identifiers, time zones, query logic, source location, and surrounding records. A screenshot without provenance may be persuasive but difficult to verify.
Context includes the producing system, tenant or host, sensor and parser, retention policy, clock condition, access path, and reason for collection. Export native records where authorized and preserve a human-readable view for interpretation. If a screenshot is necessary, record who captured it, from which interface and filter, and how it relates to the underlying record. Never crop away fields merely because they complicate the preferred explanation.
Record collection and integrity
Record the collector, method, tool version, access used, hashes where meaningful, storage location, and custody transfers. Keep originals protected and work from controlled copies. Source evaluation and corroboration still apply to internal telemetry.
Integrity controls should be proportionate to the evidence and decision. Cryptographic hashes are useful for stable files and disk images but less meaningful for a live query whose output changes. Save query text, parameters, execution time, result count, export format, and platform audit record. Use write-restricted storage, explicit case identifiers, and a custody log when material moves. A hash proves that bytes stayed the same; it does not prove that collection was complete or correctly interpreted.
Prioritize volatile evidence
Memory, active connections, running processes, cloud sessions, and short-retention logs may disappear quickly. Decide what is volatile and relevant before rebooting, isolating, or rebuilding. Collection should answer an investigation question rather than capture everything available.
Create an order of volatility for the environment and scenario. A cloud audit stream nearing retention expiry may be more urgent than a powered-off disk; a running encryption process may require immediate isolation before memory acquisition. Record current time, logged-in users, connections, processes, mounted resources, and ephemeral workload state only when authorized and useful. Broad collection increases delay, privacy exposure, storage burden, and review noise, so tie each acquisition to a question.
Balance preservation and protection
Safety can require immediate containment even when it changes evidence. Make the trade-off explicit, preserve fast context where practical, and record responder actions. Evidence preservation supports response; it must not become a reason to allow preventable harm.
Before an intrusive action, note the observed risk, decision owner, time, systems affected, and expected evidence loss. Where seconds permit, capture a console view, active-alert identifier, relevant process or session IDs, and current network state. Then act. For safety-critical, destructive, or rapidly spreading activity, containment takes priority. Later analysis must distinguish adversary changes from responder changes, so commands, isolation actions, account resets, and automated playbook steps belong in the timeline.
Protect the case record
Restrict case access, minimize unnecessary personal data, use approved storage, and follow retention and legal requirements. Document gaps and clock differences. A defensible record includes what could not be collected and how that limitation affects confidence.
Separate raw evidence from working notes and distributable findings. Apply need-to-know access, lawful retention, secure transfer, and review before sharing with vendors or partners. Correct errors without silently replacing the history: preserve the original, record the correction, and identify affected judgments. At closure, inventory the evidence, unresolved limitations, disclosure obligations, and disposal dates. Evidence quality supports technical decisions, employee fairness, regulatory response, and organizational learning; excess collection does not automatically improve any of them.