Incident Response

What to Preserve After Discovering a Security Breach

·8 min read

When a security breach is discovered, the instinct to reset passwords, reinstall systems and delete suspicious files is understandable. These actions often destroy the evidence required to understand how the incident occurred.

Authentication and access logs

Preserve authentication logs from identity providers, VPN gateways, and application login systems. These records reveal when accounts were accessed, from where, and whether access patterns changed before the incident was detected.

Application and infrastructure logs

Web server access logs, application error logs, and cloud audit trails often contain the earliest indicators of compromise. Export these before log rotation or retention policies remove them.

Endpoint and network evidence

If endpoint detection tools generated alerts, preserve those records along with firewall logs and DNS query logs. Network evidence frequently reveals command-and-control communication that endpoint tools miss.

Human observations

Document what users observed: unusual emails, unexpected prompts, changed files, or degraded performance. These observations help investigators correlate technical evidence with real-world impact.

What not to do immediately

Avoid mass password resets, system reinstalls, or deletion of suspicious files until you have guidance on evidence preservation. Each of these actions can eliminate artefacts needed to reconstruct the attack timeline.

Need incident assistance? Get help →

Want to learn this through practical investigation? Explore Pratikar training →

Related insights

Incident Response

Understanding Account Takeover Evidence

Account takeover incidents leave traces across authentication systems, email logs and application access records. Learn where to look and what patterns indicate compromise.

·7 min read
Incident Response

How to Document a Cybersecurity Incident

Clear incident documentation supports investigation, remediation and future prevention. Here is what to record and when during an active incident.

·7 min read