Before acquisition:...
 
Notifications
Clear all

Before acquisition: should first response be driven by the observed state?

1 Posts
1 Users
0 Reactions
38 Views
(@lmolinario)
New Member
Joined: 10 hours ago
Posts: 1
Topic starter   [#20784]

When approaching a powered-on computer, one of the first decisions may come before choosing an acquisition method: should the current state be maintained, or deliberately changed?

A running system may be unlocked, have encrypted volumes already mounted, contain useful volatile data, maintain authenticated sessions, or depend on network resources that may no longer be available after isolation or shutdown.

But maintaining that state is not neutral either. Processes continue to run, logs change, applications write data, synchronization may continue, and remote access or destructive activity may still be possible.

This makes the usual options difficult to reduce to a fixed sequence.

Network isolation may reduce the risk of remote interference, but it can also break active sessions or dependencies.

Live collection may preserve memory, encryption material and other volatile information, while necessarily introducing its own footprint.

Shutdown may stop ongoing activity, but it can also destroy volatile state or turn an accessible encrypted system into one that is much harder — or impossible — to access afterwards.

This makes me wonder whether first-response guidance should begin less with a predefined procedure and more with the observable state of the system.

For example:

  • power and lock state;
  • encryption and access state;
  • mounted local or remote storage;
  • active sessions;
  • network dependencies;
  • volatile information likely to be lost;
  • indications of ongoing remote or destructive activity.

The available options could then be compared in terms of what they preserve, what may be lost, what footprint they introduce, and how reversible the decision really is.

By reversible, I do not simply mean whether an action can technically be undone. I mean whether the evidential state that existed before the action can realistically be recovered.

For those who regularly deal with powered-on systems: which observable states actually make you change your normal first-response approach?

And are there situations where you deliberately maintain the current state rather than immediately isolating, collecting, or shutting the system down?

Interested to hear how others approach this in practice.



   
Quote
Share: