Why do organizations reimage machines during an incident at all?
Because it is the reliable way to re-establish trust in a compromised host. Once an attacker has had administrative access, selectively removing what was found is a bet that everything was found — and modern intrusion tooling is specifically built to survive that kind of cleanup through scheduled tasks, service registrations, firmware-level persistence and legitimate remote-management software repurposed as a backdoor. Rebuilding from known-good media removes the guesswork.
There is also operational pressure, and it is usually the stronger force. People cannot work, clinical or production systems are down, and the organization is losing money every hour. The instruction to get everyone back online arrives early and from a senior source. Reimaging is the fastest route to that outcome, which is why it frequently happens before anyone has thought about what the machine might later need to prove.
What is lost when a host is reimaged without being captured first?
The host-level record of what actually happened on that machine. That includes the filesystem timeline showing what was created, modified and accessed; deleted files still recoverable in unallocated space; the registry or configuration state showing persistence mechanisms; artefacts of program execution; browser and application history; and any attacker tooling that was on disk.
For a machine that was the point of initial access, or the one where data was staged before exfiltration, that is often the single most probative source in the matter — the place where the beginning of the intrusion or the fact of the exfiltration would be established. Losing it does not necessarily lose the case, but it converts direct evidence into inference from surrounding sources, which is a materially weaker position for whichever side needed it.
Is reimaging during an incident considered spoliation?
It depends heavily on timing, intent and what the organization knew, and it is a question for counsel on the specific facts rather than one with a general answer. The broad shape is that ordinary remediation performed in good faith, before litigation is reasonably anticipated, is treated very differently from destruction occurring after a duty to preserve has attached. Courts also distinguish between routine operational action and conduct suggesting an intent to deprive another party of the evidence.
What consistently makes the position worse is continuing to reimage after counsel is involved, after a preservation demand has arrived, or after the organization has plainly recognized it has a legal problem. What consistently makes it better is a documented, contemporaneous rationale: who decided, what the operational necessity was, what was captured before the rebuild, and what was done with the original media. The technical facts of what was and was not preserved are what the Institute can establish; the legal consequence of those facts is counsel’s call.
What can still be recovered after machines have been reimaged?
Frequently a great deal, because a host is rarely the only witness to its own behavior. Endpoint detection and response platforms retain telemetry centrally, independent of the endpoint. Firewall, proxy and DNS logs record the network side of the same activity. Identity-provider logs show the authentication history. Email gateway logs show what arrived. Backups taken before the incident may contain the pre-compromise state, and in some cases the compromise itself.
Then there is the original media, which is the question worth asking within hours rather than weeks. Organizations that swap drives and shelve the originals — or that keep the failed or replaced disks in a drawer, which is more common than any policy would suggest — retain full recoverability. Organizations that wipe and redeploy do not. The answer is often unknown to the legal team and entirely known to whoever did the work.
How long does taking a forensic image actually take?
Long enough to be inconvenient and short enough that it is almost never the real obstacle. A full disk image runs at the speed of the storage and the interface, and a typical endpoint completes in a range measured in tens of minutes to a few hours. Memory capture, which is the more perishable of the two, is usually a matter of minutes. Triage collection of the key artefacts, rather than a full image, is faster still and is often the right compromise at scale.
Against that, weigh what the alternative costs. A few hours of delay on a subset of machines, set against permanently losing the ability to establish how the intrusion began, is not a close call in most matters — and the decision is being made under pressure, by people who are not thinking about litigation, which is exactly why it should be a written policy decided in advance rather than a judgment call made at two in the morning.