{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/axis-device-compromise-evidence-cleanup-playbook/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/axis-device-compromise-evidence-cleanup-playbook/",
        "slug": "axis-device-compromise-evidence-cleanup-playbook",
        "url": "https://update.dsesecurity.com/updates/axis-device-compromise-evidence-cleanup-playbook/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/axis-device-compromise-evidence-cleanup-playbook.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/axis-device-compromise-evidence-cleanup-playbook/"
        },
        "title": "Suspected Axis device compromise: preserve evidence before cleanup",
        "summary": "Axis places evidence collection between detection and cleanup and warns that changing or powering off a suspected device can destroy information needed for investigation.",
        "format": {
            "slug": "playbook",
            "name": "Playbook"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "video-surveillance",
                "name": "Video Surveillance",
                "url": "https://update.dsesecurity.com/topic/video-surveillance/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-07-19T21:28:39+00:00",
        "modified_at": "2026-07-19T21:28:39+00:00",
        "reviewed_on": "2026-07-19",
        "reading_minutes": 2,
        "word_count": 424,
        "potentially_affected": "AXIS OS devices on active or LTS tracks when unusual access, traffic, streaming, accounts, configuration, applications, or loss of video suggests possible compromise.",
        "dse_recommendation": "Preserve device and network evidence before factory default or firmware work, then use version-appropriate Axis cleanup guidance and monitor before return to service.",
        "primary_source": {
            "name": "Axis Communications — AXIS OS Forensics Guide",
            "url": "https://help.axis.com/en-US/axis-os-forensics-guide",
            "published_on": null,
            "authority": "Axis Communications"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Axis defines a three-stage process</h2>\n<p><strong>Source fact:</strong> The AXIS OS Forensics Guide applies to AXIS OS products on active and long-term-support tracks. It organizes response into detection, evidence collection, and cleanup. That order is material: Axis warns that modifying or powering off a suspected device can destroy evidence.</p>\n<p>Axis lists indicators such as access from an unknown address, unauthorized network traffic or video streaming, unexpected file transfers, configuration changes, new accounts, lost video or audio, and unknown applications. An indicator requires investigation; it is not proof by itself that a device was compromised.</p>\n<p>The device server report contains health information, system details, configuration information, and logs. Axis identifies its downloadable archive as the primary resource for device forensic investigation. Audit logging was introduced in AXIS OS 12.7. The guide warns that a factory default clears logs held locally and recommends remote syslog to prevent that specific loss.</p>\n\n<h2>Cleanup depends on device capability</h2>\n<p>Axis describes factory default as the most efficient cleanup step for its devices after evidence is collected. For devices without signed OS and secure boot, Axis directs users to install the latest supported AXIS OS after factory default and monitor the device before reintroduction. For devices with signed OS and secure boot, Axis states that factory default returns the device to a guaranteed non-compromised state.</p>\n<p>Those are product-specific statements, not a complete enterprise incident-response plan. The guide does not replace legal preservation, organizational escalation, network forensics, credential response, or continuity planning. Containment and cleanup must also account for security coverage and any operational dependency.</p>\n\n<h2>DSE response checklist</h2>\n<p><strong>DSE recommendation:</strong> This is DSE operational synthesis. Preserve evidence and follow the organization&#8217;s incident authority before changing the device.</p>\n<ol>\n<li>Open an incident record and capture reporter, time, device identity, observed indicator, site, coverage, and business impact.</li>\n<li>Do not reboot, upgrade, reset, or install tools before the incident lead approves evidence collection.</li>\n<li>Preserve VMS, switch, firewall, DHCP, DNS, authentication, monitoring, and remote-syslog evidence around the event.</li>\n<li>Download the server report and collect available audit, system, access, certificate, application, and connection information.</li>\n<li>Hash and protect collected files under the organization&#8217;s evidence-handling procedure.</li>\n<li>Coordinate containment at an appropriate boundary without silently destroying coverage or evidence.</li>\n<li>Identify signed-OS and secure-boot support, then follow the current model-specific Axis cleanup instructions.</li>\n<li>Restore only known configuration, rotate affected credentials as authorized, validate video and events, and monitor before return.</li>\n</ol>\n\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://help.axis.com/en-US/axis-os-forensics-guide\" target=\"_blank\" rel=\"noopener noreferrer\">AXIS OS Forensics Guide</a> — indicators, evidence-preservation order, server reports, audit logs, and cleanup.</li>\n<li><a href=\"https://help.axis.com/en-US/axis-os-hardening-guide\" target=\"_blank\" rel=\"noopener noreferrer\">AXIS OS Hardening Guide</a> — current preventive controls and remote logging context.</li>\n<li><a href=\"https://help.axis.com/en-US/security-advisories\" target=\"_blank\" rel=\"noopener noreferrer\">Axis Security Advisories</a> — official vulnerability and remediation notices.</li>\n</ul>",
        "content_text": "Axis defines a three-stage process\nSource fact: The AXIS OS Forensics Guide applies to AXIS OS products on active and long-term-support tracks. It organizes response into detection, evidence collection, and cleanup. That order is material: Axis warns that modifying or powering off a suspected device can destroy evidence.\nAxis lists indicators such as access from an unknown address, unauthorized network traffic or video streaming, unexpected file transfers, configuration changes, new accounts, lost video or audio, and unknown applications. An indicator requires investigation; it is not proof by itself that a device was compromised.\nThe device server report contains health information, system details, configuration information, and logs. Axis identifies its downloadable archive as the primary resource for device forensic investigation. Audit logging was introduced in AXIS OS 12.7. The guide warns that a factory default clears logs held locally and recommends remote syslog to prevent that specific loss.\n\nCleanup depends on device capability\nAxis describes factory default as the most efficient cleanup step for its devices after evidence is collected. For devices without signed OS and secure boot, Axis directs users to install the latest supported AXIS OS after factory default and monitor the device before reintroduction. For devices with signed OS and secure boot, Axis states that factory default returns the device to a guaranteed non-compromised state.\nThose are product-specific statements, not a complete enterprise incident-response plan. The guide does not replace legal preservation, organizational escalation, network forensics, credential response, or continuity planning. Containment and cleanup must also account for security coverage and any operational dependency.\n\nDSE response checklist\nDSE recommendation: This is DSE operational synthesis. Preserve evidence and follow the organization’s incident authority before changing the device.\n\nOpen an incident record and capture reporter, time, device identity, observed indicator, site, coverage, and business impact.\nDo not reboot, upgrade, reset, or install tools before the incident lead approves evidence collection.\nPreserve VMS, switch, firewall, DHCP, DNS, authentication, monitoring, and remote-syslog evidence around the event.\nDownload the server report and collect available audit, system, access, certificate, application, and connection information.\nHash and protect collected files under the organization’s evidence-handling procedure.\nCoordinate containment at an appropriate boundary without silently destroying coverage or evidence.\nIdentify signed-OS and secure-boot support, then follow the current model-specific Axis cleanup instructions.\nRestore only known configuration, rotate affected credentials as authorized, validate video and events, and monitor before return.\n\nOfficial references\n\nAXIS OS Forensics Guide — indicators, evidence-preservation order, server reports, audit logs, and cleanup.\nAXIS OS Hardening Guide — current preventive controls and remote logging context.\nAxis Security Advisories — official vulnerability and remediation notices.",
        "content_markdown": "## Axis defines a three-stage process\n\nSource fact: The AXIS OS Forensics Guide applies to AXIS OS products on active and long-term-support tracks. It organizes response into detection, evidence collection, and cleanup. That order is material: Axis warns that modifying or powering off a suspected device can destroy evidence.\n\nAxis lists indicators such as access from an unknown address, unauthorized network traffic or video streaming, unexpected file transfers, configuration changes, new accounts, lost video or audio, and unknown applications. An indicator requires investigation; it is not proof by itself that a device was compromised.\n\nThe device server report contains health information, system details, configuration information, and logs. Axis identifies its downloadable archive as the primary resource for device forensic investigation. Audit logging was introduced in AXIS OS 12.7. The guide warns that a factory default clears logs held locally and recommends remote syslog to prevent that specific loss.\n\n## Cleanup depends on device capability\n\nAxis describes factory default as the most efficient cleanup step for its devices after evidence is collected. For devices without signed OS and secure boot, Axis directs users to install the latest supported AXIS OS after factory default and monitor the device before reintroduction. For devices with signed OS and secure boot, Axis states that factory default returns the device to a guaranteed non-compromised state.\n\nThose are product-specific statements, not a complete enterprise incident-response plan. The guide does not replace legal preservation, organizational escalation, network forensics, credential response, or continuity planning. Containment and cleanup must also account for security coverage and any operational dependency.\n\n## DSE response checklist\n\nDSE recommendation: This is DSE operational synthesis. Preserve evidence and follow the organization’s incident authority before changing the device.\n\n- Open an incident record and capture reporter, time, device identity, observed indicator, site, coverage, and business impact.\n\n- Do not reboot, upgrade, reset, or install tools before the incident lead approves evidence collection.\n\n- Preserve VMS, switch, firewall, DHCP, DNS, authentication, monitoring, and remote-syslog evidence around the event.\n\n- Download the server report and collect available audit, system, access, certificate, application, and connection information.\n\n- Hash and protect collected files under the organization’s evidence-handling procedure.\n\n- Coordinate containment at an appropriate boundary without silently destroying coverage or evidence.\n\n- Identify signed-OS and secure-boot support, then follow the current model-specific Axis cleanup instructions.\n\n- Restore only known configuration, rotate affected credentials as authorized, validate video and events, and monitor before return.\n\n## Official references\n\n- [AXIS OS Forensics Guide](https://help.axis.com/en-US/axis-os-forensics-guide) — indicators, evidence-preservation order, server reports, audit logs, and cleanup.\n\n- [AXIS OS Hardening Guide](https://help.axis.com/en-US/axis-os-hardening-guide) — current preventive controls and remote logging context.\n\n- [Axis Security Advisories](https://help.axis.com/en-US/security-advisories) — official vulnerability and remediation notices."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo.png"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/axis-device-compromise-evidence-cleanup-playbook/",
                "url": "https://update.dsesecurity.com/updates/axis-device-compromise-evidence-cleanup-playbook/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-07-19"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/axis-device-compromise-evidence-cleanup-playbook/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Suspected Axis device compromise: preserve evidence before cleanup",
                        "item": "https://update.dsesecurity.com/updates/axis-device-compromise-evidence-cleanup-playbook/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/axis-device-compromise-evidence-cleanup-playbook/#article",
                "identifier": "https://update.dsesecurity.com/updates/axis-device-compromise-evidence-cleanup-playbook/",
                "url": "https://update.dsesecurity.com/updates/axis-device-compromise-evidence-cleanup-playbook/",
                "headline": "Suspected Axis device compromise: preserve evidence before cleanup",
                "description": "Axis places evidence collection between detection and cleanup and warns that changing or powering off a suspected device can destroy information needed…",
                "abstract": "Axis places evidence collection between detection and cleanup and warns that changing or powering off a suspected device can destroy information needed for investigation.",
                "articleBody": "Axis defines a three-stage process\nSource fact: The AXIS OS Forensics Guide applies to AXIS OS products on active and long-term-support tracks. It organizes response into detection, evidence collection, and cleanup. That order is material: Axis warns that modifying or powering off a suspected device can destroy evidence.\nAxis lists indicators such as access from an unknown address, unauthorized network traffic or video streaming, unexpected file transfers, configuration changes, new accounts, lost video or audio, and unknown applications. An indicator requires investigation; it is not proof by itself that a device was compromised.\nThe device server report contains health information, system details, configuration information, and logs. Axis identifies its downloadable archive as the primary resource for device forensic investigation. Audit logging was introduced in AXIS OS 12.7. The guide warns that a factory default clears logs held locally and recommends remote syslog to prevent that specific loss.\n\nCleanup depends on device capability\nAxis describes factory default as the most efficient cleanup step for its devices after evidence is collected. For devices without signed OS and secure boot, Axis directs users to install the latest supported AXIS OS after factory default and monitor the device before reintroduction. For devices with signed OS and secure boot, Axis states that factory default returns the device to a guaranteed non-compromised state.\nThose are product-specific statements, not a complete enterprise incident-response plan. The guide does not replace legal preservation, organizational escalation, network forensics, credential response, or continuity planning. Containment and cleanup must also account for security coverage and any operational dependency.\n\nDSE response checklist\nDSE recommendation: This is DSE operational synthesis. Preserve evidence and follow the organization’s incident authority before changing the device.\n\nOpen an incident record and capture reporter, time, device identity, observed indicator, site, coverage, and business impact.\nDo not reboot, upgrade, reset, or install tools before the incident lead approves evidence collection.\nPreserve VMS, switch, firewall, DHCP, DNS, authentication, monitoring, and remote-syslog evidence around the event.\nDownload the server report and collect available audit, system, access, certificate, application, and connection information.\nHash and protect collected files under the organization’s evidence-handling procedure.\nCoordinate containment at an appropriate boundary without silently destroying coverage or evidence.\nIdentify signed-OS and secure-boot support, then follow the current model-specific Axis cleanup instructions.\nRestore only known configuration, rotate affected credentials as authorized, validate video and events, and monitor before return.\n\nOfficial references\n\nAXIS OS Forensics Guide — indicators, evidence-preservation order, server reports, audit logs, and cleanup.\nAXIS OS Hardening Guide — current preventive controls and remote logging context.\nAxis Security Advisories — official vulnerability and remediation notices.",
                "datePublished": "2026-07-19T21:28:39+00:00",
                "dateModified": "2026-07-19T21:28:39+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/axis-device-compromise-evidence-cleanup-playbook/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@id": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": "https://update.dsesecurity.com/assets/dse-updates-share.png",
                "articleSection": [
                    "Business Continuity",
                    "Cybersecurity",
                    "Video Surveillance"
                ],
                "keywords": [
                    "Business Continuity",
                    "Cybersecurity",
                    "Video Surveillance",
                    "Playbook",
                    "Advisory priority"
                ],
                "genre": "Playbook",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Video Surveillance",
                        "url": "https://update.dsesecurity.com/topic/video-surveillance/"
                    }
                ],
                "wordCount": 424,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Axis Communications — AXIS OS Forensics Guide",
                    "url": "https://help.axis.com/en-US/axis-os-forensics-guide"
                }
            }
        ]
    }
}