What to Preserve After Discovering a Security Breach
When a security breach is discovered, the instinct to reset passwords, reinstall systems and delete suspicious files is understandable. These actions often destroy the evidence required to understand how the incident occurred.
Authentication and access logs
Preserve authentication logs from identity providers, VPN gateways, and application login systems. These records reveal when accounts were accessed, from where, and whether access patterns changed before the incident was detected.
Application and infrastructure logs
Web server access logs, application error logs, and cloud audit trails often contain the earliest indicators of compromise. Export these before log rotation or retention policies remove them.
Endpoint and network evidence
If endpoint detection tools generated alerts, preserve those records along with firewall logs and DNS query logs. Network evidence frequently reveals command-and-control communication that endpoint tools miss.
Human observations
Document what users observed: unusual emails, unexpected prompts, changed files, or degraded performance. These observations help investigators correlate technical evidence with real-world impact.
What not to do immediately
Avoid mass password resets, system reinstalls, or deletion of suspicious files until you have guidance on evidence preservation. Each of these actions can eliminate artefacts needed to reconstruct the attack timeline.
Want to learn this through practical investigation? Explore Pratikar training →