Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Contain the risk without destroying evidence: coordinate with your incident-response lead, isolate the appliance using the least disruptive effective network control, and decide with trained responders whether to collect volatile evidence before shutdown. Do not assume that keeping it online or powering it off is always the safer choice.

What should you do first?

If the appliance may be compromised, treat containment and evidence preservation as competing priorities. Consider what harm it could cause while connected, what evidence a shutdown would erase, whether its live output can be trusted, and how isolation or shutdown would affect dependent services. If the incident is material or you lack forensic experience, contact an incident-response or digital-forensics professional before interacting with the device—unless urgent containment is needed to prevent harm.

  1. Coordinate. Contact the incident-response lead and relevant service or safety owners. Agree who can authorize isolation or shutdown and how to communicate without using systems that may also be compromised.
  2. Identify the appliance and its dependencies. Record its role, physical or logical identifiers, and the services or processes that rely on it. Factor in operational and safety consequences before changing connectivity or power.
  3. Choose a containment action. Ask whether a network control can isolate it effectively without changing its running state. If the appliance cannot otherwise be disconnected, CISA’s StopRansomware Guide advises powering it down as a fallback; doing so will sacrifice volatile evidence.
  4. Document actions as they happen. Record who made each decision, what changed, and when. Include the time zone and any uncertainty about the device’s clock.

Use a communication path appropriate to the incident. CISA warns that an actor may monitor activity and react to detection, so coordinate discreetly when that risk is plausible.

Should you isolate it, collect live evidence, or power it off?

There is no universal choice for every appliance. A switch, firewall, management plane, or another network control may provide a way to restrict connectivity while leaving the host running, but which control is effective depends on the actual network and device. Isolation can reduce exposure; it does not prove that the appliance is harmless or unable to affect other systems.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Option Potential benefit Main risk or limitation When to consider it
Network-only isolation Can limit the appliance’s communications while preserving its running state for possible evidence collection. May disrupt dependent services, may not block every relevant path, and does not guarantee that the device cannot cause harm. When responders can identify an effective control and the operational impact is understood.
Live evidence collection May preserve information about the system’s current operating state that would disappear on shutdown. Collection changes the system, and a compromised kernel or utility may falsify results. When the information matters, the risk of keeping the system running is acceptable, and trained responders have a suitable procedure and trusted tools.
Power down Stops the appliance from continuing to run. Erases volatile operating-state evidence, including information that may help explain recent activity. When effective disconnection is not otherwise possible or immediate harm makes shutdown necessary.

Resolve the choice in light of the specific incident: ongoing risk or spread, the importance of volatile evidence, confidence in live output, service or safety impact, and any legal, regulatory, contractual, or internal evidence requirements. If urgent harm is possible, containment takes priority; document the reason for the action.

What evidence can disappear at shutdown?

Information available only while a system is running can be lost when it is shut down or restarted. NIST SP 800-61 Rev. 1, older technical guidance, identifies categories that may be useful when relevant to an incident:

Rank #2
WintertionMicro Firewall Appliance, Mini PC,OPNsense, VPN, Router PC, Celeron N2940, 4 x I210 1GbE LAN, VGA, HDMI, SIM Slot, 0 RAM, 0 Storage, Barebone No System (Celeron N2940, 0 RAM 0 SSD Barebone)
  • equipped with celeron n2940 processor, compatible with many freebsd based router systems, linux distros, or win.os supported, easy configuration and management
  • Onboard Intel Celeron N2940 Processor, FCBGA1170 quad-core four-thread,1.83 GHz base frequency, 2 MB L2 cache, TDP 7.5 W processor
  • Please note, this is a barebone only. A system memory, a storage drive and an operating system are needed to complete this system
  • Compact aluminum, 12v3a power supply, with power cord, make sure to use a big brand memory and ssd/hdd with quality assurance
  • designed with power on/off, hdmi, 2 x usb3.0, vga, rst, 4 x lan, dc-in, size at 126 x 134 x 40.6mm Quiet, fanless design silent 100%, 0.00db noise makes an ideal deployment in small offices
  • Current network connections
  • Running processes
  • Login sessions
  • Open files
  • Network-interface configuration
  • Memory

That guidance advises collecting relevant volatile information before copying files. NIST SP 800-86 explains the trade-off: “Every action performed on the system, whether initiated by a person or by the OS itself, will almost certainly alter the volatile OS data in some way.” A live collection is therefore a deliberate forensic action, not routine browsing.

How should trained responders investigate a running appliance?

Use a known procedure and trusted tools prepared for the appliance and the incident. Avoid improvising a universal command sequence: the right collection method depends on the Linux distribution and appliance build, available access, incident scope, and whether formal evidence handling is needed. Record the visible state and every action, including tool versions, commands, outputs, and times.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Glovary N150 Mini PC Firewall (N100 Upgrade), 6 x 2.5GbE i226V LAN Fanless OPNsense Desktop Computer, DDR5 8GB RAM 256GB NVMe SSD, AES-NI, 2HD + USB-C 3 Display, 2 x M.2 NVMe Slot
  • Powerful 12th Gen N150 Processor: Glovary Firewall Box Computer with Twin Lake 12th Gen N150 Processor, 4 Cores 4 Threads, 6M Cache, up to 3.6 GHz, TDP 6W. Supports OPNsense, Linux, Openwrt, etc
  • 6 x i226V 2.5GbE Lan: Firewall router with 6 x i226-V network card, 2.5x faster than common Gigabit Ethernet. Soft Router can monitor network data, improve network security, powerful and widely used
  • DDR5 RAM 2 x M.2 NVMe Slot: Micro firewall appliance with 1 x DDR5 SO-DIMM, 2 x M.2 2280 NVMe SSD slot, 1 x SATA 3.0 for 2.5" SSD/HDD (SATA 3.0 Cable Included)
  • UHD Graphics & Triple Display: Mini PC Firewall with 2HD+Type-C triple display interfaces support 4K@60Hz, N150 processor integrated UHD Graphics. Fanless design with aluminium alloy body, quiet running without noise. Supports 12V 4 Pin 80 x 10mm small fan (Package includes 4Pin fan cable)
  • Package Contents: 1 xGlovary firewall appliance, 1 xPower adapter, 1 xSATA 3.0 cable, 1 x4pin fan cable, 1 xVESA bracket. Rich interfaces: 6 x2.5G i226V-LAN, 2 xHD, 1 xType-C, 1 xUSB3.2, 4 xUSB2.0, 1 xTF Card slot supports data storage and system boot

Do not treat plausible-looking output as proof. NIST SP 800-86 cautions: “If a system has been fully compromised, it is possible that rootkits and other malicious utilities have been installed that alter the system’s functionality at the kernel level.” A compromised kernel or user-space utility may misrepresent processes, connections, files, or other observations. Where possible, use trusted forensic tools and verify important findings using independent evidence rather than relying solely on the appliance’s own reports.

How do you preserve storage evidence?

After any justified volatile-data collection, consider acquiring a full forensic image for offline analysis. NIST SP 800-61 Rev. 1, an older incident-handling guide, recommends that a trained handler make a full disk image to sanitized write-protectable or write-once media after acquiring volatile data. It favors imaging over an ordinary file-system backup for forensic purposes because an image can retain deleted files and fragments, and can be analyzed without working on the original.

Rank #4
Glovary N150 Mini PC Firewall (N100 Upgrade), 4 x 2.5GbE i226V LAN Fanless OPNsense Desktop Computer, DDR5 8GB RAM 128GB NVMe SSD, AES-NI, 8USB Port, Support 1 to 4 NVMe Board
  • Powerful 12th Gen N150 Processor: Glovary Firewall Box Computer with Twin Lake 12th Gen N150 Processor, 4 Cores 4 Threads, 6M Cache, up to 3.6 GHz, TDP 6W. Supports OPNsense, Linux, Openwrt, etc
  • 4 x i226V 2.5GbE Lan: Firewall router with 4 x i226-V network card, 2.5x faster than common Gigabit Ethernet. Soft Router can monitor network data, improve network security, powerful and widely used
  • DDR5 RAM 2 x M.2 NVMe Slot: Micro firewall appliance with 1 x DDR5 SO-DIMM, 1 x M.2 2280 NVMe (PCIe3.0 x4) SSD slot. 1 x Multi-function M.2 slot can as 1 x M.2 x1 NVMe SSD Slot via adapter board (Default), can as 4 x M.2 x1 NVMe SSD Slot via adapter board (optional) 1 x SATA 3.0 slot (Can't be used with Multi-function M.2 Slot at the same time)
  • UHD Graphics & Dual Display: Mini PC Firewall with HD+DP dual display interfaces support 4K@60Hz, N150 processor integrated UHD Graphics. Fanless design with aluminium alloy body, quiet running without noise. Supports 12V 4 Pin 80 x 10mm small fan (Package includes 4Pin fan cable)
  • Package Contents: 1 xGlovary firewall appliance, 1 xPower adapter, 1 xSATA 3.0 cable, 1 x4pin fan cable, 1 xVESA bracket. Rich interfaces: 4 x2.5G i226V-LAN, 1 xHD, 1 xDP, 2 xUSB3.0, 6 xUSB2.0, 1 xTF Card slot supports data storage and system boot

That method may not be practical for every appliance. Storage can be integrated, inaccessible, or subject to operational constraints; do not assume that it has a removable disk or a standard SATA or USB interface. Select an acquisition method compatible with the hardware and evidence requirements. A write blocker is a specialized tool for compatible acquisition workflows, not a way to make a compromised live operating system trustworthy.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should the evidence record contain?

Keep a contemporaneous record so another responder can understand what happened and how evidence was handled. Capture:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Wintertion1U/Desktop/Rackmount Firewall Hardware,OPNsense, VPN, Network Security Appliance, Router PCN2600 D2700, 4 x Gigabit LAN, COM, VGA, Fan, 0 RAM, 0 Storage (Desktop Type, 4G RAM 64G SSD)
  • equipped with atom n2600 d2700 processor, compatible with many freebsd based router systems, linux distros, or win.os supported, easy configuration and management
  • Please note, this is a barebone only. A system memory, a storage drive and an operating system are needed to complete this system
  • 13-19 inches 1u, 50w power, with power cord, make sure to use a big brand memory and ssd/hdd with quality assurance
  • Designed with console, 2 x usb, 4 x lan, vga, power switch, size at 290 x 180 x 44mm
  • There are 2 inside reserved fans on chassis, which could be removed freely or be turned on in a high temperature environment to ensure the best function of the product
  • Appliance identifiers, location, role, and relevant system or storage details
  • Each handler’s name or identifier and their actions
  • Dates and times with time zone, including any known clock discrepancy
  • Isolation, restart, shutdown, or other changes and the reason for each
  • Tools and versions, commands, outputs, and collection method
  • Where original media, images, and collected files are stored, and who accessed or transferred them

Protect acquired material from alteration and limit access to authorized handlers. If the matter could have legal consequences, involve the organization’s legal counsel and follow its evidence-handling requirements; technical guidance is not legal advice.

When should you analyze, recover, and return the appliance to service?

Where feasible, analyze a forensic image or other preserved copy in a controlled environment rather than examining the original appliance. Do not treat a quick inspection or successful reboot as proof that the compromise is understood or removed. Establish the incident’s scope and understand persistence before deciding on recovery or return to service; appliance-specific rebuilding, validation, and operational steps depend on its hardware, role, storage, and service dependencies.

For current incident-response framing, NIST SP 800-61 Rev. 3 superseded Rev. 2 in April 2025 and places response within cybersecurity risk management. The detailed volatile-data and imaging practices described above come from NIST SP 800-86 and the older SP 800-61 Rev. 1; they should be read as legacy technical guidance, not as the latest edition of NIST’s incident-response publication.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.