A live breach is an active, ongoing security incident in which an attacker is currently connected to or operating inside a network while the investigative response is underway.
Contrast with a cold case, where the intrusion already ended and the investigator reconstructs events from saved logs, disk images, and other static evidence.
Why it matters in network forensics
- Volatility: Network flows, RAM, and active connections may disappear when the attacker disconnects or a device reboots.
- Speed vs. care: Investigators must gather evidence quickly, but not so aggressively that they alert the attacker.
- Collection style: Usually involves live response—capturing volatile data from running systems before powering them off—combined with controlled containment to preserve evidence while stopping the attack.
Live breaches sharpen the challenges described in Network Evidence Challenges, especially acquisition, content, and storage.