Web-forensics use case
Capture authenticated and restricted web content
Authenticated web evidence acquisition documents content that is visible only after authorized login or through a restricted workflow. Because access state affects what the page displays, the report should explain the account context, navigation, permissions, and collection boundaries without exposing credentials.
What this use case means
Authenticated web evidence acquisition documents content that is visible only after authorized login or through a restricted workflow. Because access state affects what the page displays, the report should explain the account context, navigation, permissions, and collection boundaries without exposing credentials.
Private portals, account dashboards, messages, cloud applications, and restricted groups can present different content to different users. Sessions expire, permissions change, and navigation may trigger updates. A capture must preserve the relevant content while protecting credentials, unrelated data, and privileged access.
Common situations
When this workflow is useful
- Documenting authorized account pages, dashboards, messages, records, or restricted groups
- Preserving web-application evidence unavailable to anonymous visitors
- Capturing content under consent, warrant, corporate authority, or another documented legal basis
Recommended process
A documented acquisition workflow
- Verify authority and account scope
Document who owns or controls the account, the authority for access, approved actions, prohibited areas, and the relevant time window.
- Prepare secure access
Use an approved account and environment. Protect credentials, multifactor codes, recovery data, and unrelated sessions from the evidence output.
- Record the authenticated context
Document the service, account identifier appropriate for reporting, access time, permissions, and navigation used to reach the relevant content.
- Capture selectively
Preserve relevant pages, interactions, downloads, source context, and session activity while minimizing unrelated private information.
- Close and report securely
Record logout or session closure where appropriate, protect the package, and describe permissions, redactions, inaccessible areas, and limitations.
Reviewable output
What the evidence package should explain
Access context
Service, account context, visible permissions, URLs, and navigation history explain why the content was available.
Restricted content
Relevant pages, messages, records, media, downloads, and interactions can be documented within the authorized scope.
Session record
Screenshots, recording, network context, and activity logs can show the acquisition sequence.
Verification material
Hashes, timestamps, custody information, and reporting support review without including secret credentials.
The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.
Professional considerations
Authority, proportionality, and limitations
- Never publish passwords, session tokens, multifactor codes, cookies, or recovery information in screenshots, reports, or example evidence.
- Access authorization must cover the actual account, content, action, and jurisdiction; technical ability is not legal authority.
- Redaction should be performed on controlled copies while the original is protected according to the case procedure.
Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.
Standards and primary guidance
Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.
Frequently asked questions
Can content behind a login be preserved?
Yes, when the investigator has appropriate authority and the acquisition method can document the authenticated session and relevant content.
Should credentials appear in the recording?
No. Plan authentication so secrets are protected. If sensitive information is inadvertently captured, secure the original and follow the approved redaction and disclosure process.
Does account access prove who created the content?
No. It documents what the authorized session displayed. Authorship or control may require provider records, account history, testimony, or other corroboration.
How should unrelated private data be handled?
Use targeted collection, access restrictions, minimization, controlled review copies, and retention rules appropriate to the investigation.