Back to Blog
Forensics
8 min read

Digital Forensics: Evidence Collection That Survives Scrutiny

The decisions made in the first hour determine whether an investigation can answer anything. Volatile data, imaging order, chain of custody, and the instinct to reboot.

GuardsArm Team

Security Experts

May 11, 2025

Digital forensics

The single most destructive thing done during an incident is rebooting the affected machine. It is also the first instinct of almost everyone, because rebooting fixes most IT problems. It destroys memory contents, running process state, network connections and often the only copy of the malware — the evidence that would have told you what happened and how far it went.

Memory first
Volatile data is lost on power-off and is often the richest source
Scope drives notification
What you can prove was NOT accessed limits the disclosure
Custody matters
Evidence handled loosely may be unusable in any proceeding

Order of volatility

Collect in the order things disappear:

Order of volatilityEvidence is collected in order of how quickly it is lost, beginning with memory and network state and ending with logs and archives.MemorysecondsNetwork statesecondsRunning processesuntil rebootDiskuntil overwrittenLogs / backupsuntil retention expires
Every minute a compromised machine stays powered on is more memory evidence, and more attacker activity.

This creates a genuine tension. Leaving a machine running preserves evidence and lets the attacker continue. The usual resolution is isolate, do not power off — remove it from the network while leaving it running, capture memory, then image the disk.

Isolate rather than shut down
Network isolation stops the attacker and preserves volatile state. A hard power-off destroys memory; a graceful shutdown lets malware run cleanup routines. Where the platform supports it, an EDR containment action is faster than unplugging the cable.

Imaging and custody

  • Write-blocked acquisition for physical media, or a provider-supported snapshot for virtual and cloud workloads
  • Hash before and after — record the hash at acquisition and verify it before analysis, to demonstrate the image is unaltered
  • Work on a copy, never the original
  • Chain of custody recording who held the evidence, when, and what they did — a contemporaneous log, not a reconstruction
  • Store securely, since forensic images of clinical systems contain PHI in bulk and are themselves a breach risk

The custody point matters even when litigation seems unlikely. A healthcare incident can become a regulatory matter, an insurance dispute or an employment case, and evidence gathered without a defensible chain may be unusable in all three.


Cloud and clinical sources

Traditional disk-and-memory forensics covers less of a modern estate than it used to.

SourceWhat it givesCatch
Cloud control plane logsWho changed the environmentOften short default retention
Identity provider logsAuthentication, token issuance, MFA eventsFrequently the most useful single source
EHR audit trailRecord-level access — decisive for notification scopeExport format varies by vendor
Email gatewayInitial access vectorRetention often shorter than dwell time
EDR telemetryProcess lineage across the estateOnly where deployed
Medical device network logsDevice behaviour, where no agent existsUsually the only telemetry available

The EHR audit trail deserves emphasis in healthcare. It is what lets you say which records were and were not accessed — and that determines how many individuals you notify. Confirm now that you can export it for an arbitrary date range, because discovering the limitations mid-incident is expensive.


The first sixty minutes

Most of the damage to an investigation is done before anyone experienced arrives. A short, agreed sequence prevents it:

DoDo not
Isolate the host from the networkPower it off or reboot it
Note the time and who did whatLog in as a domain administrator to "have a look"
Capture memory if tooling allowsRun cleanup or antivirus scans
Preserve the relevant logs before rotationDelete suspicious files
Photograph the screen if something is displayedRestore from backup over the evidence
Call the incident response contactWait until morning to escalate

The "do not log in as domain administrator" point is the one most often violated and most damaging. It puts highly privileged credentials onto a machine an attacker controls, and it overwrites artefacts while doing so.

Write this on a card
A six-line card in the on-call pack, covering isolate-do-not-reboot and who to call, prevents more evidence loss than any tooling. The person who finds the incident is rarely the person who knows the procedure.

What to prepare in advance

  • Know who to call. An incident response retainer, with the number in the printed contact sheet.
  • Decide the isolate-versus-shutdown policy before the night it matters.
  • Confirm log retention exceeds plausible dwell time — see logging strategy.
  • Establish legal privilege arrangements with counsel in advance, if you intend the investigation to be privileged.
  • Have somewhere to put images — clinical disk images are large and sensitive, and improvising storage mid-incident leads to bad choices.

GuardsArm provides incident response and forensic support for healthcare, including evidence handling that survives regulatory and legal scrutiny. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.