Digital Forensics: Evidence Collection That Survives Scrutiny
The decisions made in the first hour determine whether an investigation can answer anything. Volatile data, imaging order, chain of custody, and the instinct to reboot.
GuardsArm Team
Security Experts
The single most destructive thing done during an incident is rebooting the affected machine. It is also the first instinct of almost everyone, because rebooting fixes most IT problems. It destroys memory contents, running process state, network connections and often the only copy of the malware — the evidence that would have told you what happened and how far it went.
Order of volatility
Collect in the order things disappear:
This creates a genuine tension. Leaving a machine running preserves evidence and lets the attacker continue. The usual resolution is isolate, do not power off — remove it from the network while leaving it running, capture memory, then image the disk.
Imaging and custody
- Write-blocked acquisition for physical media, or a provider-supported snapshot for virtual and cloud workloads
- Hash before and after — record the hash at acquisition and verify it before analysis, to demonstrate the image is unaltered
- Work on a copy, never the original
- Chain of custody recording who held the evidence, when, and what they did — a contemporaneous log, not a reconstruction
- Store securely, since forensic images of clinical systems contain PHI in bulk and are themselves a breach risk
The custody point matters even when litigation seems unlikely. A healthcare incident can become a regulatory matter, an insurance dispute or an employment case, and evidence gathered without a defensible chain may be unusable in all three.
Cloud and clinical sources
Traditional disk-and-memory forensics covers less of a modern estate than it used to.
| Source | What it gives | Catch |
|---|---|---|
| Cloud control plane logs | Who changed the environment | Often short default retention |
| Identity provider logs | Authentication, token issuance, MFA events | Frequently the most useful single source |
| EHR audit trail | Record-level access — decisive for notification scope | Export format varies by vendor |
| Email gateway | Initial access vector | Retention often shorter than dwell time |
| EDR telemetry | Process lineage across the estate | Only where deployed |
| Medical device network logs | Device behaviour, where no agent exists | Usually the only telemetry available |
The EHR audit trail deserves emphasis in healthcare. It is what lets you say which records were and were not accessed — and that determines how many individuals you notify. Confirm now that you can export it for an arbitrary date range, because discovering the limitations mid-incident is expensive.
The first sixty minutes
Most of the damage to an investigation is done before anyone experienced arrives. A short, agreed sequence prevents it:
| Do | Do not |
|---|---|
| Isolate the host from the network | Power it off or reboot it |
| Note the time and who did what | Log in as a domain administrator to "have a look" |
| Capture memory if tooling allows | Run cleanup or antivirus scans |
| Preserve the relevant logs before rotation | Delete suspicious files |
| Photograph the screen if something is displayed | Restore from backup over the evidence |
| Call the incident response contact | Wait until morning to escalate |
The "do not log in as domain administrator" point is the one most often violated and most damaging. It puts highly privileged credentials onto a machine an attacker controls, and it overwrites artefacts while doing so.
What to prepare in advance
- Know who to call. An incident response retainer, with the number in the printed contact sheet.
- Decide the isolate-versus-shutdown policy before the night it matters.
- Confirm log retention exceeds plausible dwell time — see logging strategy.
- Establish legal privilege arrangements with counsel in advance, if you intend the investigation to be privileged.
- Have somewhere to put images — clinical disk images are large and sensitive, and improvising storage mid-incident leads to bad choices.
GuardsArm provides incident response and forensic support for healthcare, including evidence handling that survives regulatory and legal scrutiny. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


