Lesson 1 of 2 in Do Not Destroy the Evidence · 3 min left in this chapter
The Instinct That Destroys the Case
Rebooting is the first thing everybody reaches for, and it throws away the only copy of what was running.
4 min read
Not yet reviewed
It is seven in the morning. Your site is showing somebody else's message, or your hosting provider has emailed about outbound spam, or a customer has asked why your login page looks different. Your hand is already moving toward the reboot button.
That instinct is correct about the goal and wrong about the order. You do want the site back. But a running machine is holding the only copy of several things that will not survive the power cycle, and once they are gone no amount of later work brings them back.
Note
This is the one lesson in the course with no commands in it. The skill here is a pause, and it is the hardest one to teach — everything else you will learn is only possible if you take it.
What dies with the power
A compromised machine is not just a filesystem. Most of what tells you what is happening lives in memory, and memory is not written down.
Gone on reboot
Which processes are running, and what command started them
Open network connections, and who is on the other end
A program running from a file it already deleted
Anything decrypted, including keys held only in RAM
The attacker's shell, if they are still holding itStill there afterwards
Files on disk, and their timestamps
Logs that were flushed before the reboot
Anything the attacker deliberately left behindThe left-hand column is most of the answer to "what is happening right now". The right-hand column is most of the answer to "what happened", which is a different and slower question.
The sharpest example is a process running from a deleted file. An attacker starts their program, then deletes it from disk. The file is gone from every listing, but the running process still holds it open — so while the machine is up the kernel will hand you the binary back, and once it is down it never existed.
$ ls -l /tmp/.x
ls: cannot access '/tmp/.x': No such file or directory
$ ls -l /proc/2481/exe
lrwxrwxrwx 1 root root 0 Aug 14 07:12 /proc/2481/exe -> '/tmp/.x (deleted)'
$ cp /proc/2481/exe /evidence/recovered-2481
$ sha256sum /evidence/recovered-2481
9f2b1c4e... /evidence/recovered-2481
Reboot that machine and every line above stops working. The process is gone, /proc/2481 is gone, and the only copy of the thing that was running on your server has been deleted by you rather than by the attacker.
But the site is defaced right now. Am I really supposed to leave it up while I take notes?
Sometimes yes and sometimes no, and knowing which is the actual skill. That is the next lesson. What I want you to take from this one is narrower: reboot is not a neutral first move. It is a decision that throws information away, so make it deliberately rather than reflexively.
Restoring from backup has the same problem, twice
Wiping the box and restoring last night's backup feels safer than a reboot. It is usually worse, for two reasons that compound. The first is the same one: you have destroyed the evidence, and now you cannot answer how they got in. The second is that you do not know *when* the compromise happened, so you do not know whether last night's backup already contains it — and restoring a backdoored backup gets you a clean-looking site that is still theirs.
Take care
Restoring before you know the compromise date is the single most common way an incident repeats a week later. The timeline is not academic — it is what tells you which backup is safe, and you cannot build it from a machine you have already wiped.
Your VPS is serving a defaced page. Which single action destroys the most information you cannot get back?
There is one honest exception, and it is not a technical one. If what is on the screen is doing active harm — illegal content, or something that puts a person in danger — it comes down first and the forensics happen afterwards. That judgement is the subject of the next lesson.
Tip
If you remember one sentence from this chapter, make it this: snapshot first, then act. Almost every hosting provider can take a disk snapshot of a running VPS in under a minute, and it costs pennies. It is the cheapest insurance in this entire course.