Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
You can’t tell from an alert alone. Treat it as a lead, start your incident-response plan, contain affected systems deliberately, and preserve evidence while responders establish what happened. Don’t describe the event as a confirmed data breach unless the evidence and your organization’s criteria support that conclusion.
What should you do first after a suspicious security alert?
At 02:13, the immediate job is not to solve the whole incident or decide what to tell the public. It is to make the next safe decisions, get the right people involved, and preserve the facts needed to determine what happened.
- Record the alert before changing anything. Note when it triggered, what system or account it concerns, the alert’s source, and the evidence visible to you. Preserve the alert details in the approved incident record or another secure location.
- Separate observations from conclusions. Write down what is confirmed, what appears likely, and what remains unknown. For example: “The endpoint tool flagged a suspicious process on host X” is an observation; “customer data was stolen” is a conclusion that requires evidence.
- Activate the response plan and contact tree. Contact the designated incident lead, security or IT team, and any managed incident-response provider identified in the plan. Follow the approved escalation route if the primary contact is unavailable.
- Use a trusted communication channel. If the event may involve compromised email, identity, or collaboration accounts, use the out-of-band method specified by your plan. Keep a record of decisions, actions, times, and who authorized them.
- Hold off on cleanup. Don’t delete files, reimage a machine, run improvised cleanup tools, or make broad configuration changes before the response lead has considered evidence needs and containment.
NIST’s finalized SP 800-61 Revision 3, published April 3, 2025, supersedes Revision 2 and aligns incident response with Cybersecurity Framework 2.0. NIST says, “Incident response is a critical part of cybersecurity risk management and should be integrated across organizational operations.” NIST’s announcement of SP 800-61r3 explains the revision.
Recommended Free Tools
Does an alert mean there was a breach?
No. An alert may indicate suspicious activity, a security control firing, or a potential incident. By itself, it does not establish that an attacker accessed information, that data left the organization, or that a legal or contractual breach has occurred.
#1 Best Overall
- ENDLESS POWER FROM SOLAR ENERGY: Just 45 minutes of direct sunlight powers the camera for a full day of use, while the built-in battery lasts up to 180 days on a single charge during cloudy days. Solar charging requires temperatures above 32°F.△
- EASY WIRE-FREE INSTALLATION: Place the Tapo SolarCam C402 KIT where you need it without relying on nearby outlets. Install the camera and solar panel together or separately using the included 13 ft cable for flexible placement.
- PRIORITIZE WHAT MATTERS: Set activity zones to monitor specific areas for motion or people. Free person and motion detection helps reduce unwanted alerts and notifies you when activity is detected.
- VERSATILE VIDEO STORAGE: Store footage locally via a microSD card (up to 512GB)* or via cloud with a Tapo Care cloud subscription. Tailor your security to suit your needs, whether indoor or outdoor, you have the storage option you need.
- FULL-COLOR 1080P, DAY AND NIGHT: See clearly in low light with a large-aperture lens and built-in spotlights. Capture full-color night vision up to 30 ft away to monitor for possible intruders or motion.
Use the definitions and decision criteria in your organization’s incident-response plan. Until responders have enough evidence to apply them, describe the event as suspected or under investigation rather than confirmed. Keep these categories distinct in the incident record:
- Confirmed: directly observed facts, such as the alert, affected asset, or activity established in available logs.
- Suspected or likely: a reasoned assessment based on current indicators, clearly marked as an assessment rather than a proven fact.
- Unknown: questions not yet answered, such as whether an account was used successfully, which systems were reached, or whether data was accessed or transferred.
That distinction is useful both technically and operationally: it lets responders act urgently without overstating what is known.
Rank #2
- Outdoor 4 is our most affordable wireless smart security camera yet, offering up to two-year battery life for around-the-clock peace of mind. Local storage not included with Sync Module Core.
- See and speak from the Blink app — Experience 1080p HD live view, infrared night vision, and crisp two-way audio.
- Two-year battery life — Set up in minutes and get up to two years of power with the included AA Energizer lithium batteries and a Blink Sync Module Core.
- Enhanced motion detection — Be alerted to motion faster from your smartphone with dual-zone, enhanced motion detection.
- Person detection — Get alerts when a person is detected with embedded computer vision (CV) as part of an optional Blink Subscription Plan (sold separately).
Should you take the affected system offline?
Containment can limit further harm, but the method and scope matter. CISA’s #StopRansomware Guide, a joint resource involving CISA, MS-ISAC, NSA, and FBI, recommends isolating impacted systems. It notes that broad network isolation may be appropriate when multiple systems or subnets appear affected. Its response checklist is ransomware-focused, so apply it as a practical reference—not as a claim that every incident follows the same technical sequence.
| Action | When it may fit | Main trade-off |
|---|---|---|
| Isolate an identified system from the network | Responders have identified an affected host and can coordinate a controlled disconnection. | Can limit spread or ongoing access; may interrupt service and should be coordinated with the incident lead. |
| Expand isolation to a network segment or multiple systems | Evidence indicates several systems or subnets may be affected, and the response team judges wider containment necessary. | May constrain an incident more broadly, but can disrupt critical services and dependencies. |
| Power down a system | Use only when the approved plan and qualified responders determine it is necessary—for example, when network disconnection is not possible. | Powering down can destroy volatile-memory evidence. CISA describes it as a fallback when disconnection is not possible. |
When feasible, coordinated network disconnection is generally the first containment route described by CISA rather than casually shutting down a host. Don’t make a unilateral, organization-wide shutdown decision based only on one alert. Weigh observed spread against service continuity and safety, and use out-of-band communications if normal channels may be compromised.
Rank #3
- 【2K High Definition】Capture every detail inside your home with crystal-clear 2K high definition video with this indoor security camera. Easily see what your baby is holding or what your pet is playing with.Controller Type:Amazon Alexa;Android;Google Assistant.Connectivity protocol:Wi-Fi.Power source type:Corded Electric, Power Adapter: 100–240 V. Connects via 2.4GHz Wi-Fi Band
- 【Up, Down, All Around】This Pan/Tilt camera see everything across an entire room or walkway with the 360° horizontal and 114° vertical range pan/tilt field of view.
- 【Detection & Instant Notification】Get instant push notifications when motion, person or baby crying is detected, there is no additional fee to use it as a baby camera monitor. Discern from notifications that matter, so you'll know if its your pet playing around or if someone is actually there.
- 【Works w/ Alexa & Google Assistant】Fully compatible with Amazon Alexa and Google Assistant, use your simple voice command to view Tapo indoor security camera live stream on Echo Show or Google Chrome Cast with a screen. Streaming via Google limited to display on Chromecast & Nest devices only.
- 【2-Way Audio w/ Built In Siren】Never truly leave home with the built-in 2-way audio. Use as a pet camera with phone app to comfort your pet from anywhere in the world. Keep your family safe with cameras for home security indoor by warding off intruders.
How do you preserve evidence during a cyber incident?
Preservation is not a reason to leave an active threat unchecked; it is a reason to coordinate containment with evidence handling. Tell the incident lead what actions have already been taken and when. Follow your organization’s evidence procedures, and involve qualified responders before attempting forensic collection if you are not trained to do it.
- Protect short-retention records. Prioritize potentially volatile or easily overwritten evidence, including memory, Windows Security logs, and firewall log buffers.
- Retain relevant sources. Identify available endpoint, network, cloud, and identity logs that may show activity before and after the alert. CISA’s business logging guidance recommends logging to support earlier detection.
- Ask responders about collection. Depending on the event, they may consider memory capture or a system image. Collection methods and priorities depend on the system, incident, and approved procedures.
- Keep a decision trail. Record who approved containment or other changes, what was changed, when it happened, and the reason. Preserve logs and alert records in the approved location.
Who should you escalate to—and when?
Use the incident plan and contact tree rather than improvising a notification list. CISA recommends a designated crisis-response team with technology, communications, legal, and business-continuity roles, and advises keeping leadership informed and coordinating internal and external responders.
Rank #4
- 【2K Resolution & Color Night Vision】This 2K Ultra HD security camera is designed for indoors and outdoors. You can choose to install indoor and outdoor cameras for home security in the kitchen, living room, bedroom, baby room, yard, garage, etc. You can not only capture high-definition surveillance footage through the security camera outdoor during the day, but also see colorful images at night. The outdoor camera provides comprehensive and multi period services for your home security.
- 【Two-way Talk & Motion Detection】The outdoor security camera is equipped with a noise-canceling microphone and speaker. You can have a remote talk with family, pet or unexpected visitor on the wifi camera side through the phone app. The house cameras with audio and video will bring you an unexpected user experience. Once the motion is detected, the indoor camera will send you a notification via the phone app. If strangers break into home, the built-in siren will help you deter the intruders.
- 【IP65 Waterproof & Easy to install】The outdoor cameras for home security, which have an IP65 waterproof design, so in any weather, there is no need to worry about the outdoor cameras being damaged. The security camera outdoor with dust and water resistance that can be easily installed on walls, shelves, trees, roofs, and other places you want, helping you to keep an eye on your home security anytime and anywhere.
- 【24/7 SD Card Storage & Optional Cloud】 The wifi outdoor camera features in-app 10s alert video clips or pictures. It also supports TF card (up to 128GB, not included) or cloud storage (with a 30-day trial). Both storage ways allow for 24/7 continuous recording, ensuring that you can play back your videos whenever you want. This indoor camera also has advanced encryption technology to protect your privacy, so even if the home security cameras are stolen, no one can access your recorded videos.
- 【Work with Alexa Assistance】The cameras for home security, which can also work with Alexa assistant. If you have third parties at home, you can connect the wifi camera with them, use your simple voice command to view the indoor security camera live stream on Echo Show or other Alexa devices with a screen. Easily get your home security footage up on a larger TV display.
- Security/IT and incident leadership: to validate the alert, coordinate containment, and establish scope.
- Legal counsel: when the facts may involve regulated or sensitive information, contractual duties, or external reporting. Notification obligations depend on jurisdiction, sector, data, contracts, and incident facts; there is no universal deadline to infer from an alert.
- Business continuity and service owners: when isolation or recovery could affect critical services, safety, or operational dependencies.
- Communications and leadership: when the event may affect employees, customers, partners, or organizational operations. Coordinate messages with incident leadership and counsel; distinguish confirmed facts from open questions.
- Insurer or external response specialists: if the organization’s policy or plan calls for their involvement. Use the required contacts and procedures.
- Government assistance: contact CISA, the FBI, or other channels identified by your plan when appropriate. A serious incident may require specialist support and jurisdiction-specific legal advice.
How should you scope the incident?
Once the initial response is underway, build a working picture of what may be affected. Treat it as provisional and update it as evidence arrives.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →- Which systems, accounts, network segments, cloud services, or business processes are implicated?
- What activity is confirmed, and what is only suspected?
- Do available records indicate successful access, movement to other systems, or access to particular data? What evidence would answer those questions?
- Which critical services, safety functions, or dependencies could be affected by containment?
- What evidence may expire or be overwritten if not preserved promptly?
Prioritize work according to observed risk, criticality, and safety—not simply the order in which alerts arrived. Keep unresolved questions visible so that responders and decision-makers do not mistake an incomplete picture for a settled one.
When is it safe to recover?
Recovery should follow containment and a plan, not just the disappearance of an alert. CISA’s ransomware-focused guide recommends restoring from clean backups, prioritizing critical systems, documenting lessons, and preventing reinfection. Apply those steps to the incident at hand, with qualified responders validating that recovery is appropriate.
- Confirm the threat is contained and understand which systems and dependencies need recovery.
- Verify that the intended backups and restoration sources are suitable; do not assume a backup is clean without checking it.
- Sequence restoration around critical services and safety requirements.
- Monitor restored systems and retain the records needed to investigate and improve the response.
CISA’s guide also points organizations toward applicable notification requirements and counsel. Whether notice is required, to whom, and by when cannot be determined without the facts and the relevant legal, regulatory, and contractual context.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

