Forensic collection script for volatile host evidence

7552
0

During incidents I want a repeatable evidence collection script that preserves volatile context before a system changes again. Time, network state, processes, and recent logs usually matter immediately. Good collection is quiet, timestamped, and resistant to operator improvisation under stress.