Logs roll over in days. Memory is gone at reboot. Remediation destroys the record it is fixing — and all three happen before most matters have counsel.
Start a conversation with the Incident Concierge, already scoped to incident response & forensics. Select a subject area to prompt it, or describe the incident directly.
Incident response creates two problems at once that pull in opposite directions. The security imperative is to contain and remediate immediately: isolate the host, rotate the credentials, reimage the machine, restore from backup. The evidentiary imperative is that every one of those actions destroys the record of what happened. Volatile memory — where the running malware, the live network connections and the decrypted keys are — does not survive a reboot. Log retention is frequently thirty days and often less, so by the time an intrusion is discovered the earliest evidence may already have aged out. A reimaged host is forensically gone. None of this argues against responding quickly; it argues for capturing before you cure, and for someone raising that in the first hours rather than the second week.
What to preserve and when, how response adequacy is judged, and how far attribution honestly goes.
The most time-critical page on this site. What disappears, how fast, and what to do in the first hours.
investigateJudged on what was known at each moment — not on the timeline as it reads afterward.
investigateWhat was actually reached matters more than who did it — and is far harder to establish than assumed.
investigateHow the Institute approaches response — what the analysis needs, never an assessment of a live incident.
Faster than almost anyone moves. Volatile memory first, because it disappears the moment a machine is rebooted and it holds the running malware, live connections and sometimes decrypted credentials. Then a forensic image of affected systems before any reimaging. Then logs — and this is the one that catches organizations out, because retention is commonly thirty days and sometimes seven, so the earliest and most important evidence of initial access may age out while the response is still underway. A written litigation hold covering security telemetry, and an immediate instruction to suspend log rotation, are the two cheapest things anyone can do on day one.
It can, and the tension is real rather than theoretical. Isolating and reimaging a compromised host is correct security practice and it ends the forensic record on that host. Restoring from backup overwrites the compromised state. Rotating credentials is essential and removes the ability to observe how they were being used. The resolution is sequencing rather than choosing: capture first, then cure. A forensic image takes a fraction of the time people assume, and an organization that images before remediating retains both its security response and its evidence.
Against what the organization knew at each point, not against the completed timeline. The analysis asks whether detection was reasonable given the monitoring in place, whether containment followed within a reasonable period of detection, whether the scope investigation was competent, and whether notification obligations were met on their own clocks. The most common criticism is not slowness but scope: an organization that contained what it found without establishing what else the attacker reached frequently discovers more later, and that second discovery is far more damaging than the first.
Rarely with the confidence people want, and overclaiming here is a serious credibility risk. Forensic evidence usually supports statements about tooling, technique and infrastructure — that the activity is consistent with a known pattern — and rather less often supports naming a specific actor. Infrastructure is rented and shared, tools leak and are reused, and false flags exist. For most civil matters attribution also matters less than it feels like it should: what drives the case is what was accessed, when, and whether the safeguards were reasonable, none of which depends on knowing the attacker's identity.
Describe what has happened and what has been done. The Institute will help you see what is at risk.