Skip to content

CERT-Cyberross · 6 min read

What we preserve first, and why the order matters

The evidence acquisition sequence our responders follow in the first hour, and the reasoning behind it.

Published

  • Incident response
  • Forensics

The single most expensive mistake in the first hour of an incident is not a wrong containment decision. It is destroying evidence that would have made every subsequent decision cheaper.

Volatile memory comes first, because it is the only place where an in-memory-only payload exists at all, and it disappears the moment someone follows the instinct to power the machine down. Isolating a host from the network preserves memory; shutting it down does not.

Logs come second, and specifically the ones with the shortest retention. Firewall, VPN and identity-provider logs frequently roll off within days. By the time a forensic team is formally engaged, the window that would have established initial access has often already closed.

Disk images come third. This surprises people, because imaging feels like the definitive forensic act — but disk is the least volatile artefact in the estate and will still be there tomorrow. Sequencing acquisition by volatility, rather than by perceived importance, is what keeps the timeline reconstructable.

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.