Web-forensics use case
Forensic acquisition of CCTV footage from a web portal
Eviquire Desktop Expert can support the documented acquisition of CCTV footage presented through an authorized browser-accessible surveillance portal. The workflow can preserve the portal context, investigator navigation, observed playback, authorized video exports, network information, hashes, timestamps, and custody records. Eviquire does not acquire directly from a camera, DVR, NVR, storage disk, proprietary desktop client, or vendor backend that is not exposed through the web interface.
What this use case means
Eviquire Desktop Expert can support the documented acquisition of CCTV footage presented through an authorized browser-accessible surveillance portal. The workflow can preserve the portal context, investigator navigation, observed playback, authorized video exports, network information, hashes, timestamps, and custody records. Eviquire does not acquire directly from a camera, DVR, NVR, storage disk, proprietary desktop client, or vendor backend that is not exposed through the web interface.
CCTV portal evidence is more than the visible video. Camera identity, site or zone, portal account, selected date range, displayed timezone, playback controls, stream quality, event markers, export settings, and the relationship between observed playback and a downloaded file can all affect interpretation. Browser portals may use segmented or transcoded streams, dynamic timelines, short retention periods, proprietary export formats, or vendor-specific players, so the examiner must document both what the portal displayed and the limitations of the acquisition.
Common situations
When this workflow is useful
- Preserving incident footage available through a cloud CCTV, VMS, building-security, retail, transport, or access-control web portal
- Documenting how an authorized operator located, filtered, played, and exported footage for litigation, insurance, workplace, compliance, or criminal investigation
- Capturing expiring or remotely hosted footage before the portal retention period, permissions, or available recordings change
Recommended process
A documented acquisition workflow
- Confirm authority, scope, and retention
Document the legal or organizational authority, portal tenant, authorized account, relevant site and cameras, incident period, timezone, expected retention deadline, export permissions, and excluded areas before accessing footage.
- Validate browser compatibility and access
Confirm that the target portal works through Eviquire’s integrated browser using the required network or VPN, SSO, MFA, proxy, client certificate, and supported video technology. A portal that requires a proprietary desktop client, unsupported browser plug-in, or direct recorder access may require another forensic method.
- Prepare the acquisition environment
Create the case and acquisition record, identify the workstation, operating system, Eviquire version, investigator, portal URL, time source and timezone, network route, and required recording options. Verify Internet access for licensing and configured evidence-timestamping services.
- Establish the footage context
Navigate from the portal entry point to the relevant organization, location, camera, event, date, and time interval. Preserve the camera label and identifier, portal filters, displayed timezone, playback speed, quality, overlays, and other settings that affect what is shown.
- Record and acquire the relevant playback
Use acquisition-session video to document the search and playback sequence. Play the relevant interval at an appropriate quality and speed, record buffering or missing segments, and make targeted captures of important frames and surrounding portal information without presenting the session recording as the original camera file.
- Export the native portal artifact when available
Use the portal’s authorized export or download function to preserve the available native or vendor-generated video, still image, report, metadata, or archive. Record the selected cameras, start and end times, export options, filename, format, and the investigator action that generated the file, then preserve its cryptographic hash.
- Verify, close, and transfer the case
Check that the expected artifacts are present and playable with the appropriate authorized software, document failures or dependencies, close the case, verify integrity, and export it with the Portable Viewer or transfer it under the approved chain-of-custody procedure for independent review.
Technical guidance
Conditions that affect a CCTV portal acquisition
Validate the portal, video technology, time settings, export path, and evidential scope before the formal acquisition begins.
Browser-based scope
A practical suitability test is whether the authorized footage can be searched, played, and exported through a conventional standards-based web browser. Eviquire must be able to perform the relevant portal workflow through its integrated forensic browser.
- Suitable: browser-accessible CCTV, VMS, cloud-camera, or security portals.
- May be unsuitable: portals that depend on a proprietary thick client, unsupported legacy plug-in, hardware decoder, or direct DVR/NVR console.
- Not a device acquisition: Eviquire does not image camera memory, recorder disks, or the surveillance backend.
Authentication and network access
Private portals can be reached through an authorized workstation and corporate VPN when Eviquire’s browser can satisfy the same routing, authentication, proxy, and certificate requirements. Test SSO, MFA, account permissions, and any IP or device restrictions before formal collection.
- Use a specifically authorized account and record its role without exposing credentials.
- Confirm access to both the CCTV portal and required Eviquire licensing or timestamping services.
- Document VPN, proxy, certificate, region, and account conditions that could affect the available cameras or recordings.
Playback and acquisition-session video
The acquisition-session recording can show how the examiner selected the camera and time range, used the timeline, started playback, expanded the player, changed controls, and initiated an export. It is a continuous record of the portal interaction and observed playback.
- Distinguish Eviquire’s session recording from the original or portal-exported CCTV file.
- Record playback speed, quality, overlays, audio state, buffering, skipped intervals, and any investigator-controlled zoom or enhancement.
- Avoid unnecessary transformations when the objective is to document what the portal originally presented.
Network recording
When Wireshark is installed and permitted, Eviquire can preserve packet-level traffic associated with the web acquisition. This may help document the portal endpoints and delivery activity, although encrypted traffic and segmented streaming can limit what packet inspection alone reveals. Without Wireshark, supported application-layer web and network-session context can still accompany the visible acquisition.
- Eviquire with Wireshark: packet-level capture for the authorized session.
- Eviquire without Wireshark: supported application-layer and web-session context.
- Network capture does not by itself establish that a stream is the recorder’s original native file.
Exports, formats, and playback dependencies
A CCTV portal may export MP4, AVI, MOV, MKV, still images, ZIP archives, reports, metadata files, or a proprietary evidence package. Preserve the downloaded file exactly as supplied and retain any authorized vendor player, codec information, manifest, or verification instructions needed for later review.
- Record the export’s camera selection, start and end times, timezone, quality, format, and filename.
- Hash the original downloaded artifact before creating converted or working copies.
- Clearly label transcoded, clipped, annotated, redacted, or converted derivatives and preserve the untouched export.
Time, camera identity, and corroboration
The portal may display time according to the camera, recorder, site, tenant, authenticated user, browser, or workstation configuration. Daylight-saving changes and clock drift can also affect interpretation. Preserve the displayed time and timezone and document the relevant portal settings when available.
- Distinguish acquisition time, displayed footage time, and any export-file timestamps.
- Record camera name, identifier, site or zone, and the navigation path that connected the footage to that camera.
- Where event time or originality is disputed, correlate the portal acquisition with recorder audit logs, access logs, export logs, system configuration, or direct device evidence obtained under an appropriate method.
Reviewable output
What the evidence package should explain
Portal and camera context
The authenticated portal, URL, organization or site, camera identity, timeline, filters, playback controls, overlays, and navigation sequence explain where the footage was found.
Observed playback record
Acquisition-session video, screenshots, relevant frames, audio state, buffering notes, and playback settings document what the investigator observed through the portal.
Exported footage and integrity
Authorized video exports, stills, reports, metadata, or archives can be preserved in their supplied formats with hashes, timestamps, and the documented export action.
Technical and custody record
Environment details, supported network context, optional packet capture, acquisition history, case reports, integrity verification, and chain-of-custody records support later review.
The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.
Professional considerations
Authority, proportionality, and limitations
- CCTV footage can contain highly sensitive personal data. Define authority, necessity, relevant cameras and time ranges, access controls, retention, disclosure, redaction, and secure transfer before collection.
- A portal acquisition preserves what the authorized web system presented and exported; it does not independently prove that the footage is the recorder’s untouched original or that its displayed time is accurate.
- Do not claim completeness when footage is missing, expired, overwritten, inaccessible, buffered, low quality, outside the selected interval, or unavailable because of permissions or portal limitations.
- Preserve original portal exports unchanged. Perform clipping, conversion, enhancement, annotation, or redaction only on controlled derivatives while retaining their relationship to the original artifact.
Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.
Standards and primary guidance
Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.
Frequently asked questions
Can Eviquire acquire CCTV footage from a web portal?
Yes, when the authorized CCTV or video-management portal is accessible and operable through Eviquire’s integrated browser. Compatibility should be verified before the formal acquisition, particularly for portals using proprietary players or legacy plug-ins.
Is the Eviquire session recording the original CCTV video?
No. It documents what was displayed and what the investigator did during the portal session. When available and authorized, the portal’s native or vendor-generated export should also be preserved as a separate original artifact.
Can Eviquire acquire directly from a DVR or NVR?
No. Eviquire is a web-evidence acquisition product, not a hardware or storage-imaging tool. Direct recorder, camera, disk, or backend acquisition requires an appropriate surveillance-system or digital-forensic procedure.
What should be recorded about CCTV timestamps?
Record the displayed date and time, timezone, camera and site, selected interval, portal or user timezone settings, and any known clock offset or daylight-saving issue. Important times may need correlation with recorder or system logs.
What if the portal only provides a proprietary video format?
Preserve the original downloaded package exactly as supplied, hash it, and retain authorized information about the required vendor player, codec, manifest, or verification method. Create viewable derivatives only as documented working copies.
Is Wireshark required for a CCTV portal acquisition?
Wireshark is needed when packet-level network capture is required and permitted. Without it, Eviquire can still preserve the visible portal acquisition, session recording, downloaded artifacts, and supported application-layer web and network-session context.
Can another examiner review the acquired footage?
Yes. The closed case and preserved artifacts can be transferred under the approved procedure, reviewed through the Portable Viewer where applicable, or imported into another authorized Eviquire Desktop Expert installation. Proprietary CCTV exports may also require the vendor’s authorized player.
Does Eviquire prove that a CCTV recording is authentic?
Eviquire documents and protects the integrity of what was acquired through the portal. Authenticity conclusions may also require camera or recorder configuration, audit and export logs, direct system evidence, witness information, and examiner analysis.
Who uses this workflow?
Relevant professional roles
This acquisition workflow is commonly relevant to these teams. The appropriate authority, scope, procedure, and review requirements still depend on the matter.
Law enforcement
Preserve volatile online evidence for authorized criminal and intelligence investigations.
See role-specific guidance →Journalists and NGOs
Document public-interest material before it is edited, deleted, restricted, or blocked.
See role-specific guidance →Forensic experts
Acquire online evidence with technical context, integrity verification, custody records, and reporting.
See role-specific guidance →Law firms
Preserve websites and online content for litigation, disclosure, legal holds, and expert review.
See role-specific guidance →