QUANTUMCYBEROPSQuantum Intelligence. Cyber Resilience.Request assessment

QuantumCyberOps Research · 14 minute read

Digital Forensics and Incident Response Checklist

An evidence-preservation and investigation checklist for devices, memory, identity, email, network, cloud, and application logs.

Reviewed 2026-08-29Editorial methodology

Protect people, operations, and evidence

Activate the incident lead and use an out-of-band communications channel if corporate identity or email may be compromised. Record who identified the incident, when it was observed, actions already taken, and systems that may be affected.

Do not wipe, reimage, power-cycle, or casually explore a device before deciding whether volatile evidence is required. Containment must balance operational harm against the risk of destroying evidence or alerting an active adversary.

Preserve devices and volatile data

Document device identity, user, location, power state, network state, visible applications, and connected media. Where appropriate and legally authorized, collect memory before disk images because memory can contain active processes, network connections, encryption keys, injected code, and credentials.

Use validated acquisition methods, hash evidence, maintain a chain-of-custody record, protect originals, and conduct analysis on verified working copies.

Collect logs before retention windows expire

Prioritize identity-provider audit logs, endpoint telemetry, email security events, firewall and proxy records, DNS, VPN, cloud control-plane logs, SaaS audit trails, application logs, database activity, and backup history.

Normalize time zones and preserve original timestamps. Record collection queries, exports, account permissions, tool versions, and gaps so the resulting timeline remains defensible.

Investigate and recover with evidence

Develop hypotheses and test them across independent evidence sources. Establish initial access, execution, persistence, privilege changes, lateral movement, data access, command and control, and impact. Clearly separate confirmed facts, analytical judgments, and unknowns.

Recovery should remove persistence, rotate exposed secrets, close the root cause, validate clean systems, restore monitoring, and define heightened observation. Retain evidence according to legal, contractual, privacy, and insurance requirements.

Related professional capability

When independent evidence, specialist tooling, or defensible reporting is required, review our related service and scope the work confidentially.