Kit · Incident
Evidence & forensics kit
The discipline that decides whether your investigation stands up later. Most evidence is lost in the first twenty minutes, by people acting reasonably and in good faith.
- Applies
- From first suspicion
- Principle
- Volatile first, document always
The first twenty minutes
The instinct on finding a compromised host is to reboot it, or to run a scan, or to log in and look around. Each of those destroys evidence — memory contents, volatile artefacts, timestamps. Decide the collection order before the incident, because nobody makes this decision well under pressure.
Collection sequence
Collect in order of volatility — most perishable first. Containment can wait the few minutes this takes, unless active harm is ongoing.
Chain of custody record
An unbroken record of who held what, when, and what they did with it. Gaps are what opposing parties look for.
Decisions to make before the incident
| Question | Why it must be pre-decided |
|---|---|
| Who authorises taking a production system offline for imaging? | During an incident this becomes a business negotiation. Pre-authorise it, with conditions. |
| Where is evidence stored, and who can access it? | Evidence stored on the compromised estate is not evidence. |
| What is our retention period for incident evidence? | Too short and you lose a case; too long and you create a data protection liability. |
| At what point do we involve legal counsel? | Legal privilege considerations change how the investigation is documented, and privilege cannot be applied retroactively. |
| Who talks to law enforcement, and when? | An unplanned first contact tends to become a commitment nobody authorised. |
| Do we have the capability in-house, or do we call someone? | Establish the retained relationship before the incident. Procurement is slow at 02:00. |
Next kit
Exercise & assurance kit
Table-top and technical exercise design, the efficacy test for your detection stack, and how to turn findings into closed actions.