The first rule is to preserve evidence. Do not reboot a potentially compromised system before capturing its current state unless immediate containment requires it.

Restrict network communication, preserve event logs, and record the discovery time. Check adjacent systems for the same indicators.

After containment, identify the original entry point and close it before returning the system to the trusted environment.