Network Isolation
Definition
Disconnecting a compromised host from all network interfaces while leaving it powered on. Preserves volatile memory contents but removes the attacker's communication path. The preferred containment method when forensic investigation must follow.
- Action
- Disconnect host from network, keep it powered on
- Preserves
- Volatile memory contents
- Removes
- Attacker communication path
- Use case
- Preferred when forensic investigation will follow
Common questions
Why not simply power off a compromised machine instead?+
Powering off destroys volatile memory, which can hold encryption keys, running processes, and malware artefacts that are never written to disk.
What is the tradeoff of network isolation versus full shutdown?+
The host stays live and could still run local malicious code, so isolation trades some containment completeness for the ability to preserve memory evidence.
Related terms
- Attacker-Alerting Risk
- The risk that a containment action signals to the attacker that they have been detected, potentially triggering destructive countermeasures on systems they...
- Short-Term Containment
- Immediate actions taken after incident confirmation to stop an attack from spreading, without waiting for full scope analysis. Distinguished from long-term containment,...
- Traffic Blocking
- Adding firewall rules, null routes, or DNS sinkholes to deny communication between attacker-controlled infrastructure and the victim network. Effective against external command-and-control...
- VLAN Segmentation
- Moving a compromised device or subnet into a separate VLAN with restrictive access control lists, limiting lateral movement to other network segments...
- Volatile Evidence
- Data that exists only while a system is running: active processes, logged-in sessions, network socket state, decryption keys in memory, and command...