Skip to content
Forensics

Preserving digital evidence: what to save before responders arrive

In the gap between discovering an incident and professional response, evidence either survives or it doesn't. You don't need forensic tools — you need to stop destruction.

Preserving digital evidence: what to save before responders arrive — Response Red advisory illustration

The essentials

  • The best preservation is not touching things: isolate affected systems, then leave them alone.
  • Memory disappears at power-off, and logs silently overwrite themselves within days or even hours — these two losses are permanent.
  • Phone photos of screens, with timestamps, are legitimate and genuinely useful evidence.
  • Never work on the evidence: no antivirus scans, cleanups, updates, or casual logins on affected machines.
  • A handwritten timeline made today beats a reconstructed one made next week.

Digital evidence is fragile in a way physical evidence is not: it destroys itself on a schedule. Logs rotate, memory clears, backups expire, and every well-meaning click on an affected system overwrites something an investigator needed.

You do not need forensic training in this window. Almost everything that matters comes down to preventing destruction — most of it by people trying to help.

Do this now

  1. Freeze the scene. Isolate affected machines from the network and leave them powered on. From this moment, nobody logs into them, scans them, or "just checks something".
  2. Rescue the logs. Logs are usually the first evidence to die. Extend retention where you can, and export firewall, VPN, identity, cloud audit, and mail logs covering at least the past month.
  3. Photograph what is on screen. Ransom notes, error messages, strange windows — capture them with a phone. The photo's own metadata provides a timestamp; note which machine each shot came from.
  4. Start the incident log. One document, one owner. Times (note your timezone), what was observed, what was done, who decided. This log anchors the entire later investigation — and your legal account of it.
  5. Secure physical media. Label and set aside relevant laptops, drives, and USB devices. Never plug a suspect USB device into another machine to "see what's on it".
  6. Record what was already changed. If someone rebooted a server or deleted a file before you knew better, write it down — honestly and precisely. Investigators can work around known changes; unknown ones poison conclusions.

What not to do

  • Do not run antivirus cleanups or delete malware files — they are the attacker's fingerprints.
  • Do not reboot, patch, or update affected machines.
  • Do not restore backups over compromised systems before they are imaged.
  • Do not forward suspicious emails — export them as files with headers intact.
  • Do not examine suspect USB drives or devices on other machines.

Preserve the evidence

Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:

  • Volatile state: running affected machines, left isolated and powered on — the highest priority.
  • Rotating logs: firewall, VPN, identity provider, cloud audit, mail — exported now.
  • Affected disks and devices, physically secured and labeled.
  • Suspicious emails exported with full headers.
  • The human record: your incident log and screen photographs.

Keep a clear head

The urge to clean up and get back to work is the most destructive instinct in incident response. Activity feels like progress; here, restraint is the professional move. Doing less, carefully, keeps every option open.

If it helps the team hold still: think of the environment as a crime scene that happens to be made of computers. Nobody debates whether to mop a crime scene.

Questions victims ask

Is a phone photo of a screen really evidence?

Yes. It proves what was displayed, where, and when, and it captures state that may be gone an hour later. It complements — never replaces — forensic imaging, but in the first hours it is often the only capture anyone can safely make.

We already wiped one machine. Is preservation pointless now?

No. Investigations are mosaics — logs, other machines, cloud trails, and email records all still hold pieces. Preserve everything that remains and tell responders exactly what was wiped and when; known gaps are manageable, hidden ones are not.

Does chain of custody matter for a company that isn't going to court?

You don't yet know whether you're going to court — insurance disputes, regulatory inquiries, and litigation often surface months later. Basic discipline now (who handled what, when, kept where) costs minutes and preserves every future option.

When the first hour is over, we take it from there.

Scoping, containment, forensics, and recovery — expert-led and evidence-safe, with AI removing the waiting. Engage a responder or talk to us about readiness.