Quick answer
The evidence that explains a breach starts disappearing before anyone even opens a ticket. — volatile memory, session logs, and default-retention firewall data are gone within days, and by the time a formal investigation starts, a lot of the trail is already unrecoverable.
- Breaches still take 241 days on average to identify and contain, far longer than most logs are kept.
- Missing logs due to short retention doubled year over year in incident response cases reviewed in 2025.
- The turn: the biggest forensic gap isn’t a missing tool. It’s a clock nobody set on purpose.
A laptop gets flagged for unusual activity on a Friday afternoon.
IT isolates it, opens a ticket, and moves on. The investigation gets scheduled for Monday.
By Monday, the machine has been rebooted twice — once by a well-meaning technician, once by an automatic update.
The memory that held the attacker’s session is gone. So is half the network log that would have shown where the traffic went.
Nobody destroyed evidence on purpose. It just expired, the way it always does when nobody is racing the clock.
The clock nobody set on purpose
Most incident response plans focus on containment: isolate the device, block the account, rotate the credentials. That part usually works.
What gets skipped is the fact that containment and preservation are not the same action — and doing one without the other can quietly erase the ability to explain what happened.
Put those three together and the pattern is obvious: the investigation almost always starts after the evidence window has already closed on part of the story.
What actually goes invisible, and how fast
Volatile memory
RAM holds the attacker’s live session, decrypted payloads, and process activity that never touches disk. A reboot — even an automatic one — wipes it completely and permanently.
Firewall and network session logs
Default retention on a lot of firewall appliances is seven days. Some are set to 24 hours. If the investigation opens on day eight, that path is closed for good.
Endpoint process history
What ran, when, launched by what — this is exactly what shows how an attacker moved between machines. Most endpoints don’t keep it long unless something is explicitly recording it.
Cloud and identity provider logs
Login history and API activity from SaaS platforms often live on a rolling window too. Without an export, that record ages out the same as everything else.
“We contained it” answers one question. “We can show exactly how it happened, on what machines, and when” answers the one an auditor, a regulator, or a cyber insurer actually asks. Only one of those requires evidence that survives past the first day.
Containment stops the damage. Only preservation lets you prove what the damage was.
Fragmented evidence makes the case, one source doesn’t
Even when logs survive, they’re rarely in one place. Palo Alto Networks’ Unit 42 reviewed its 2025 incident response caseload and found investigators needed evidence from two or more distinct sources to establish what happened in 87% of cases — sometimes as many as ten.
Endpoint telemetry, firewall logs, identity provider records, cloud audit trails. Each one alone tells part of the story. None of them, alone, tells all of it.
That’s the real argument for centralizing endpoint evidence before an incident happens, not during one. Reconstructing a timeline from five disconnected consoles under deadline pressure is where investigations lose days they don’t have.
What to lock down in the first 24 hours
- Stop the reboot reflex.The instinct to restart a compromised machine is the single most common way volatile memory gets destroyed before anyone captures it.
- Snapshot before you isolate.Pull a memory image and a disk snapshot before changing network state, not after — isolation itself can trigger cleanup scripts on some malware.
- Export the logs that expire soonest.Firewall and identity provider logs on short retention windows need to be pulled out immediately, before the rolling window closes on their own schedule.
- Write down the chain of custody from minute one.Who touched the device, when, and what they did to it. Evidence without a documented chain is evidence a court or an insurer can challenge.
Standard forensic practice collects evidence in order of volatility — memory, then network state, then disk, then archived logs — because each layer decays at a different speed. A response plan that jumps straight to disk imaging is already working with an incomplete picture.
How INGITE helps
Cloud Digital Forensics Investigation
Keeps endpoint activity, process history, and event timelines centralized and retained, so an investigation that starts on day eight can still see what happened on day one.
Cloud EndPoint Security
Flags anomalous behavior and isolates devices without requiring a reboot, so the machine stays contained and its memory stays intact for the investigation that follows.
If an incident started right now, would the evidence still be there tomorrow?
Not whether you’d contain it. Whether, a week from now, you could show exactly what happened and prove it.
- Does your incident response plan separate containment steps from preservation steps?
- Do you know the retention window on every log source you’d need — firewall, identity provider, endpoint?
- Is there a written rule against rebooting a suspect machine before memory is captured?
If the honest answer to any of those is “we’d figure it out in the moment,” the gap isn’t your response speed. It’s that nobody set the clock before it started running.
What is the most important evidence to preserve in the first 24 hours of an incident?
How long does it take to detect and contain a data breach in 2026?
Why do incident investigations rely on more than one log source?
Should a compromised device be rebooted before an investigation starts?
Make sure the evidence survives long enough to matter
Cloud Digital Forensics Investigation keeps endpoint history and event timelines centralized, so an investigation started days later still has a day-one picture to work from.