2. Preservation
Securing the scene and initial preservation
A scene in an office is rarely dramatic: a desk, a docking station, a workstation or laptop, a phone, perhaps a drawer of USB sticks and a server room down the corridor. It is still a scene, and it is at its most fragile in the first hour, when colleagues are curious and the user may still have access.
First actions on encountering a workstation
- Stop. Do not touch the keyboard, mouse, screen, cables or power. Do not sit at the desk.
- Look and record. Note the power state, what is on screen, whether a user is logged in, any link lights on network ports, and any activity (disk light, fan noise, a progress bar).
- Photograph everything before anything is moved (section 3).
- Decide the power-state question (below) and the isolation method (section 4). These two decisions shape everything that follows, so make them deliberately and write down the reasoning.
- Only then begin acquisition, in the order set out in sections 6 to 8.
Establish physical access control
- Decide the boundary of the scene and say it out loud: this desk, this office, this rack. Equipment at a home address is a separate scene with its own authority.
- Put one named person in charge of the scene. Everyone else asks that person before entering or touching anything.
- Where you can, lock the room or cordon the area. Where you cannot, keep someone physically present until every device has been collected.
Restrict unauthorised access
- Ask the security or IT team to suspend the user's accounts, badge and remote access at the same moment the scene is secured, not before (which tips them off) and not long after (which gives them time to act). This is a coordinated step, agreed with HR and legal in advance.
- Do not let colleagues "tidy up" or retrieve their own belongings from the area until you have documented it.
- Assume the machine can be reached remotely until you have isolated it (section 4).
Establish who has already interacted with the equipment
Before you arrive, someone has usually already touched the machine: the manager who found it, the IT engineer who "just checked something", the colleague who closed the lid. Find out, in this order, and record the answers with names and times:
- Who has been at the desk since the matter was raised, and what did they do? Ask specifically about logging in, moving the mouse, closing windows, plugging or unplugging anything, and shutting down or restarting.
- Has anyone connected to the machine remotely, including automated tools such as endpoint management, antivirus scans or backup agents?
- Has the machine been powered off or restarted since the matter was raised? If so, by whom and how?
These answers are observed facts about the scene, not accusations. They explain artefacts you will later find (a logon at 09:14 by the IT engineer's account) and they are far easier to obtain on the day than months later.
Keep an entry and exit log
From the moment the scene is secured, record every person who enters or leaves: name, role, time in, time out and reason. Keep it on paper or on a device that is not part of the evidence.
The power-state decision
Whether the workstation is on or off is the single most consequential observed fact at the scene, because it determines what evidence still exists and what your first acquisition must be.
If the machine is powered off, it normally stays off. Powering it on boots the operating system, which writes to the disk, may run scheduled tasks or scripts, may start a sync client, and on an encrypted system may consume a boot counter or trigger a lockout. Nothing is gained: a powered-off machine holds no volatile evidence to capture, and its storage can be imaged without booting it. The only usual exception is a deliberate, authorised decision to boot a forensic copy in a virtual machine later, in the laboratory, never the original.
If the machine is powered on, do not shut it down until volatile evidence has been captured. Shutting down destroys the contents of memory: running processes, network connections, logged-in sessions, unsaved documents, malware that exists only in memory, and, critically, the keys to any encrypted volume that is currently unlocked. On a workstation with full-disk encryption, a shutdown may turn a readable disk into one that cannot be decrypted without a key you do not have. Section 7 sets out what to capture and in what order. Once that is done, the shutdown method is itself a decision to record: a graceful shutdown writes to disk and may run shutdown scripts; removing power avoids those writes but leaves the filesystem in whatever state it was in, which journalling filesystems tolerate well. For a workstation with encryption or suspected malware, removing power after memory capture is usually preferred. For a server or a machine with an unusual filesystem, seek advice first.
If the machine is powered on but the screen is locked, the session and its encryption keys are still in memory, but software memory capture needs an unlocked session to run. Do not guess the password. Isolate the machine, keep it powered, and pursue credentials through legitimate channels (the user, an administrator account, or the recovery sources in section 12); logging in with a lawfully obtained credential is a documented live interaction like any other. Hardware-assisted memory acquisition exists but is specialist work. If no route to an unlocked session is available in reasonable time, capture what can be seen, record the decision, and proceed to shutdown and physical imaging, accepting that the volume may not be decryptable later. Sections 13 to 15 give the platform-specific steps.
Example. A workstation is found powered on with the screen locked. The BitLocker recovery key is not held by IT. Shutting it down now would leave a fully encrypted disk and no key. Leaving it on, isolating it from the network and capturing memory first gives a realistic chance of recovering the volume key from RAM. The decision, the reasons and the time are written in the notes before anything is done.
3. Documentation
Initial documentation
Documentation starts before acquisition and continues after it. The first pass captures the scene exactly as found, because within an hour it will no longer be as found.
Photograph devices and their surroundings
- Wide shots of the whole area first, then each device, then details: cables, ports, labels, screens, sticky notes and anything that looks like a password or a recovery key.
- Photograph the screen of any powered-on device before you touch it, including the lock screen, error messages, open windows, notifications and the system clock if visible.
- Photograph every connected peripheral and storage device in place: docking station, monitors, external drives, USB devices, card readers, and which port each occupies.
- Photograph the back and underside of every device for serial numbers and asset tags. Include a scale where size matters.
- Use a camera that records the time in the image metadata, and check that its clock is correct first. Note any offset.
Record device condition and state
For every device, before it is moved, note:
- Make, model, serial number, asset tag and any visible damage or signs of the case having been opened.
- Power state: on, off, sleeping, hibernating, screen locked, screen unlocked. A dark screen is not the same as off; look for power lights and fan noise.
- Logged-in user, if shown, and any other user names visible on a lock or switch-user screen.
- Visible applications, documents, dialogue boxes and notifications.
- Connections: mains, network cable, docking station, external drives, phones, USB devices, and which port each uses.
- Network state: link lights on the Ethernet port, wireless indicators, VPN or remote-access client icons, network name if shown.
- Encryption indicators: a BitLocker, FileVault or LUKS prompt, a pre-boot authentication screen, a padlock icon on a drive, a third-party encryption client in the system tray.
Record times, dates and your own actions
- Write down the date, the time you arrived, the time the scene was secured and the time each device was collected. Use one time source for the whole scene and say which it was.
- Compare each device's clock to your reference clock and note the difference. Timeline analysis later depends on it.
- Keep contemporaneous notes: what you did, in what order, and why. "14:12, disconnected Ethernet cable from port 1 after photographing link state, to prevent remote access; screen remained locked" is the standard to aim for.
- Never rewrite notes afterwards. Add corrections as dated additions.
Example. A workstation shows a file transfer dialogue at 63 per cent, copying to a drive labelled "E:". That single photograph, with the system clock in shot and your reference time in your notes, is an observed fact of the first importance. It also tells you the external drive is being written to right now and must not be unplugged casually.
4. Preservation
Network isolation
A live workstation that can still reach a network is a workstation that can still be changed from outside. Isolation is the first preservation action after documentation, and it must be done in a way that alters the machine's state as little as possible.
What you are protecting against
- Remote wiping. Endpoint management, mobile device management and some consumer services can wipe a machine on command. A user who knows an investigation has started may issue that command.
- Cloud synchronisation. A sync client will upload local changes and download remote ones, including deletions made elsewhere, altering the local state you are trying to preserve.
- Remote access. Remote desktop, remote support tools and SSH allow someone else to act on the machine while you are standing in front of it.
- Command-and-control activity. If the machine is compromised, malware may receive instructions, exfiltrate data or remove itself once it detects investigation.
- Evidence modification. Time synchronisation, update agents, backup agents and scheduled jobs all write to the machine on a schedule and all depend on the network.
Every live interaction changes state
There is no zero-footprint way to touch a running computer. Unplugging a cable causes the operating system to log a link-down event and may cause applications to react. Running a tool loads it into memory, overwriting whatever was there. The objective is therefore not "no change" but the smallest necessary change, understood in advance and documented at the time. A change you can explain in court ("I disconnected the cable; the system logged a link-down event at 14:12; nothing else was altered") is unavoidable alteration. A change you cannot explain, or did not need to make, is contamination.
Prefer physical isolation
In order of preference:
- Disconnect the Ethernet cable at the workstation end, after photographing the port, the cable and the link lights. This is a single, well-understood event with a minimal footprint.
- Use hardware wireless controls. Some laptops have a physical radio switch; use it and photograph the position. External wireless adaptors can be unplugged after photographing them. Neither involves the operating system's user interface.
- Apply RF isolation where the device has an internal wireless adaptor and no hardware switch, and where remote wiping or continued connectivity is a real risk: a Faraday bag or enclosure for a laptop, or a shielded workspace. Note that a machine inside a Faraday bag may increase its transmit power and drain its battery faster, and that mains power must be provided through a filtered feed or the bag defeats itself; use this where it is justified and planned, not as a reflex.
- Software isolation as a last resort. Aeroplane mode, disabling an adaptor in the operating system or disconnecting from a wireless network all involve interacting with the user interface, which changes state (input events, registry or configuration writes, possible dismissal of a screen saver). Use it only when no physical method is available, do the minimum, and record every click.
Where the workstation is connected through a docking station, disconnecting the dock's uplink is equivalent to unplugging the cable, provided the laptop has no other active adaptor. Where the machine is a virtual machine, isolation is done at the hypervisor (disconnecting the virtual network adaptor), which also has the advantage of leaving the guest's state untouched.
Bluetooth and other radios
Bluetooth, mobile broadband and near-field radios are rarely a route for remote wiping of a workstation, but a mobile broadband adaptor is a network connection like any other. Treat it as such: remove it or shield it.
Example. A laptop is on a docking station with a wired connection and an internal wireless adaptor with no hardware switch. The examiner photographs the dock, disconnects the dock's Ethernet uplink, and records the time. Rather than opening the operating system's network settings, the examiner places the open laptop in a shielded enclosure with a filtered mains feed, records that too, and proceeds to memory capture. The only alterations are a link-down event and, possibly, a wireless roaming attempt, both of which are noted.