Web-forensics use case

Capture authenticated and restricted web content

Authenticated web evidence acquisition documents content that is visible only after authorized login or through a restricted workflow. Because access state affects what the page displays, the report should explain the account context, navigation, permissions, and collection boundaries without exposing credentials.

What this use case means

Authenticated web evidence acquisition documents content that is visible only after authorized login or through a restricted workflow. Because access state affects what the page displays, the report should explain the account context, navigation, permissions, and collection boundaries without exposing credentials.

Private portals, account dashboards, messages, cloud applications, and restricted groups can present different content to different users. Sessions expire, permissions change, and navigation may trigger updates. A capture must preserve the relevant content while protecting credentials, unrelated data, and privileged access.

Common situations

When this workflow is useful

  • Documenting authorized account pages, dashboards, messages, records, or restricted groups
  • Preserving web-application evidence unavailable to anonymous visitors
  • Capturing content under consent, warrant, corporate authority, or another documented legal basis

Recommended process

A documented acquisition workflow

  1. Verify authority and account scope

    Document who owns or controls the account, the authority for access, approved actions, prohibited areas, and the relevant time window.

  2. Prepare secure access

    Use an approved account and environment. Protect credentials, multifactor codes, recovery data, and unrelated sessions from the evidence output.

  3. Record the authenticated context

    Document the service, account identifier appropriate for reporting, access time, permissions, and navigation used to reach the relevant content.

  4. Capture selectively

    Preserve relevant pages, interactions, downloads, source context, and session activity while minimizing unrelated private information.

  5. Close and report securely

    Record logout or session closure where appropriate, protect the package, and describe permissions, redactions, inaccessible areas, and limitations.

Reviewable output

What the evidence package should explain

Access context

Service, account context, visible permissions, URLs, and navigation history explain why the content was available.

Restricted content

Relevant pages, messages, records, media, downloads, and interactions can be documented within the authorized scope.

Session record

Screenshots, recording, network context, and activity logs can show the acquisition sequence.

Verification material

Hashes, timestamps, custody information, and reporting support review without including secret credentials.

The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.

Professional considerations

Authority, proportionality, and limitations

  • Never publish passwords, session tokens, multifactor codes, cookies, or recovery information in screenshots, reports, or example evidence.
  • Access authorization must cover the actual account, content, action, and jurisdiction; technical ability is not legal authority.
  • Redaction should be performed on controlled copies while the original is protected according to the case procedure.

Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.

Standards and primary guidance

Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.

Frequently asked questions

Can content behind a login be preserved?

Yes, when the investigator has appropriate authority and the acquisition method can document the authenticated session and relevant content.

Should credentials appear in the recording?

No. Plan authentication so secrets are protected. If sensitive information is inadvertently captured, secure the original and follow the approved redaction and disclosure process.

Does account access prove who created the content?

No. It documents what the authorized session displayed. Authorship or control may require provider records, account history, testimony, or other corroboration.

How should unrelated private data be handled?

Use targeted collection, access restrictions, minimization, controlled review copies, and retention rules appropriate to the investigation.

Privacy preferences

Essential storage remembers this preference and is always active. Optional third-party services are disabled unless you allow them.