Investigation Decisions - AWS Security Incident Response Guide

Investigation Decisions

At this point, you can choose between an offline investigation (immediately shutting down the instance) or an online investigation (keeping the instance running). One advantage to the offline investigation is that after the instance is shut down, it can no longer affect the existing environment. Additionally, you can create a copy of the affected instance from the EBS snapshots, and review it in an isolated AWS account with an isolated environment that is designed specifically for your investigation. However, you can choose to not shut down the instance immediately, if an online investigation enables you to potentially capture volatile evidence from the host operating system, such as memory or network traffic.