Eviquire capabilities
Web and digital evidence acquisition, from collection to review.
Eviquire brings live web capture, crawling, video recording, network traffic capture, multimedia acquisition, evidence integrity, case review, and reporting together in a documented workflow for professional investigations.
A capability set designed around investigative evidence—not just screenshots.
Online evidence can be volatile, dynamic, authenticated, or spread across linked pages, feeds, video, email, and applications. Eviquire provides purpose-built collection and review capabilities so an examiner can preserve the material, explain the acquisition conditions, and prepare it for review. Feature availability varies by plan, platform, deployment, source, and configuration.
Core feature highlights
Purpose-built tools for evidence collection and review.
Case Manager
Organize cases, acquisitions, and evidence in one structured workspace.
Forensic reports
Prepare reportable output for closed cases, acquisitions, and evidence.
Case Viewer
Review portable case packages created on another supported machine.
Evidence workflow
Work with evidence-handling principles informed by ISO/IEC 27037 and SWGDE guidance.
Chain of custody
Record collection settings, user activity, and events throughout acquisition.
Triple hashing
Use three cryptographic hash algorithms to help verify preserved evidence.
Evidence timestamping
Record time information during acquisition and support timestamp verification.
Video recording
Record browser or application windows with synchronized cursor and click indicators.
Network traffic capture
Collect network traffic and related technical context during an acquisition.
Full-page capture
Capture pages that extend beyond a single visible screen.
Smart auto-scroll
Collect content from long and continuously loading pages, including social feeds.
Web-page archive
Preserve source content in a web-page archive format when relevant.
Live web capture
Acquire live websites and web applications with visible, full-page, and region-based options.
Bulk URL collection
Acquire a defined sequence of URLs and preserve downloaded files as evidence items.
Web crawling
Collect same-domain, linked, paginated, and product-listing pages with a trace of scanned pages.
Deep web resources
Review raw resources, HTTP exchanges, headers, robots.txt, sitemaps, and TLS context.
Social-media collection
Use collection workflows for Telegram, Facebook, Reddit, YouTube comments, and related content.
Email and mobile
Acquire live POP3 or IMAP email and record Android screens through USB.
Secure routing
Control proxy routing and use built-in Tor and Onion Network support when appropriate.
Languages and deployment
Use localized workflows across supported desktop, cloud, and portable review environments.
Capability library
Explore the Eviquire feature set
Web and digital evidence acquisition
Collect live web content with the context needed for later review.
- Live websites and web applications
- Visible-screen, manual-region, full-page, and region-based captures
- Automatic page, element, and social-feed scrolling
- Sequential bulk acquisition of multiple URLs
- Individual preservation of downloaded files and automatic image extraction
- Browser and application-window recording with cursor and click indicators
- Multi-monitor capture and immediate operation cancellation
Crawling and linked-content collection
Extend a collection beyond a single URL while retaining a record of the pages scanned.
- Same-domain and one-level-deep crawling
- Multipage and paginated-site crawling
- User-defined Next navigation controls
- Product-listing link extraction and individual product-page collection
- Hybrid Clicker and Crawler acquisition mode
- Tracking of every page scanned during crawling
Deep web-resource and network context
Preserve relevant resources and technical signals that may not be apparent in the visible page alone.
- Raw resource capture while content is in transit
- HTTP requests, responses, headers, and downloaded content review
- Network traffic capture during acquisition sessions
- Automatic robots.txt and sitemap collection
- TLS certificate metadata export and system-information collection
- Resources suited to cyber-threat intelligence and web-malware investigations
Video, audio, social, email, and mobile
Use task-specific workflows for content that changes quickly or lives outside a conventional web page.
- Video and screen recording through FFmpeg-based window capture
- Process-scoped application audio and synchronized cursor/click indicators
- Current-page video detection and video downloading from 200+ platforms
- Telegram Web acquisition, autoscroll, file extraction, and user-list CSV export
- Facebook, Reddit, and YouTube comment-expansion support
- Live POP3 and IMAP email acquisition
- Live Android screen recording through USB
Integrity and chain of custody
Document how evidence was acquired and help reviewers verify that the package has not changed.
- Evidence hashing with three algorithms (triple hash)
- Real-time evidence timestamping and multi-blockchain forensic-package timestamping where enabled
- Cryptographic timestamping through FreeTSA
- Automatic hash and timestamp verification during case import
- Chain-of-custody records for user agent, settings, events, comments, and completion
- Tracking of failed or corrupted acquisitions
- Content-review reminders and FreeTSA validation instructions
- Workflow references ISO/IEC 27037 evidence handling and SWGDE Best Practices for Acquiring Online Content
Review, reporting, and case handoff
Prepare captured material for examiner review, client communication, or a portable case handoff.
- Case Manager for organizing cases, acquisitions, and evidence
- Acquisition Review with screenshots, files, request, and response review
- Evidence comments, user-activity audit logs, and per-evidence acquisition-report details
- PDF download, print, Save As, copy-evidence-URL, and A4 printable-screenshot controls
- Custom report branding and logos
- Portable Windows Case Review tool and portable Case Viewer packages
- Case review summaries plus acquisition type and timezone display
Privacy, routing, and operator tools
Control the acquisition environment and make repeated collection work more efficient.
- Integrated proxy manager, bulk-acquisition proxy routing, and Web/SOCKS proxy support
- Built-in Tor and Onion Network support
- TLS metadata that can assist in detecting local man-in-the-middle proxies
- Settings Expander with live preview and browser-style navigation
- Split-screen collection for side-by-side sites or User Agent String comparison
- URL normalization, protocol completion, and context-menu actions
- Keyboard shortcuts for screenshots, page shots, scrolling, and crawling
Language, platform, and deployment
Select a deployment and localized workflow appropriate to the investigation environment.
- Localized interface and acquisition reports
- Content-language selection for English, Spanish, Arabic, Hindi, Italian, German, Romanian, French, Portuguese, and Lithuanian
- Windows 10 and 11, Ubuntu 22.04, and macOS beta support
- Virtual-machine support plus desktop, cloud, and portable case-review deployment options
- Floating subscriptions for licensed desktop plans
- Community edition availability and support for cases larger than 10 GB
Use evidence-acquisition features responsibly
These capabilities support a documented, repeatable workflow. Investigators must have appropriate legal authority, follow organizational policy, preserve the conditions needed for their case, and apply validated procedures appropriate to their jurisdiction.
Frequently asked questions
What is forensic web acquisition?
It is a controlled process for collecting web-based content while preserving sufficient technical context to explain how the material was obtained.
Why does Eviquire not use a browser extension to collect evidence?
A browser extension can be convenient for saving visible content, but it operates inside the browser and does not provide the independent acquisition environment or complete network-traffic capture required for a robust forensic workflow. Eviquire uses a dedicated acquisition application so it can document the visible content alongside relevant HTTP requests and responses, headers, downloaded resources, acquisition settings, timestamps, hashes, and chain-of-custody activity. Extensions may assist routine capture, but they should not be treated as a substitute for a documented forensic acquisition.
Can Eviquire collect content beyond a visible screenshot?
Yes. Two core Eviquire capabilities are acquisition-session video recording and network-traffic capture, giving the acquisition a record of both what occurred on screen and relevant technical exchanges during collection. The evidence package can also include full-page and region captures, scrolling workflows, source and web-page archives, HTTP requests and responses, headers, downloaded files and resources, URLs, metadata, acquisition settings, timestamps, hashes, activity records, and chain-of-custody information. The appropriate method and artifacts depend on the source and case.
Are all capabilities available in every deployment and plan?
No. Capability availability can depend on the edition, operating system, deployment, source platform, configuration, account permissions, and commercial plan. Confirm the requirements relevant to your workflow before purchasing or relying on a feature.
How do ISO/IEC 27037 and SWGDE relate to Eviquire?
Eviquire's evidence workflow references ISO/IEC 27037 digital-evidence handling principles and SWGDE Best Practices for Acquiring Online Content. Teams remain responsible for validating procedures, their implementation, and suitability for the governing legal or organizational requirements.
Do the features guarantee admissibility?
No. A tool cannot guarantee admissibility; applicable rules, facts, process, and examiner evidence determine how collected material is assessed.