About this module
Evidence can disappear in the first few minutes after an incident. This module explains why employees should stop, leave the device running, avoid cleanup, and capture what they can safely see. Learners are given practical evidence habits: take a photo of the screen, write down the time, save suspicious messages, and note what changed. The lesson also explains what not to do, including power cycling, wiping files, or experimenting with suspicious links. Preserving evidence helps investigators rebuild the story.
Key takeaways
What you do in the first five minutes after finding something wrong can decide whether the investigation that follows even has a chance. The moment you suspect a device is compromised, stop. Resist the urge to shut it down, close anything, or clean it up. Every action erases something forensics might have needed to see. If a device looks compromised, leave it running.
Cutting the power wipes out everything active at that instant, exactly what forensics needs most to see. As tempting as a clean slate sounds, resist it. Starting fresh removes the exact fingerprints that show how someone got in and what they touched along the way. Whatever caught your attention, leave it alone.
What looks like the obvious problem is very often the exact proof investigators need to reconstruct what happened. There are three safe moves here. Grab your phone and capture what's on the display right now. Jot down when you first noticed something was wrong. And if you're able to, pull the network cable or flip off Wi-Fi, that's as far as your involvement should go.
Start by capturing the screen, precisely how you found it, before anything closes or refreshes. Resist closing anything. Leave every window and program running right where they are. Write down what caught your eye, and the exact moment you saw it. Then it goes straight to I.T. or forensics, in the same condition you found it.
That's the entire job: preserve, document, and pass it along. Custody has to move cleanly from one set of hands to the next. You spot it and leave it be. I.T. signs for it and takes over. Forensics tracks every single transfer before examining anything. And legal can only use what stayed provably intact the whole way through. A few numbers worth holding onto.
Nothing gets erased on your own initiative, the device never gets restarted by you, and every single handoff, from your desk all the way to legal, needs a paper trail behind it. Forensics teams live by a simple rule: untouched evidence is the strongest evidence there is. Your job is to protect that, not to tidy it up.
The instinct to jump in, tidy things up, or reboot the machine feels productive, but it's exactly backwards. The better move is to leave things precisely as they are and get I.T. on the phone right away.
Here's the whole playbook: leave the device exactly as it is, capture what's on the screen, note the moment you saw it, and get it into the right hands, untouched. What you preserve in the first few minutes can make or break everything that follows. Leave it alone, document it, and let the people trained for this take it from here.



