Web-forensics use case

Forensic acquisition of CCTV footage from a web portal

Eviquire Desktop Expert can support the documented acquisition of CCTV footage presented through an authorized browser-accessible surveillance portal. The workflow can preserve the portal context, investigator navigation, observed playback, authorized video exports, network information, hashes, timestamps, and custody records. Eviquire does not acquire directly from a camera, DVR, NVR, storage disk, proprietary desktop client, or vendor backend that is not exposed through the web interface.

What this use case means

Eviquire Desktop Expert can support the documented acquisition of CCTV footage presented through an authorized browser-accessible surveillance portal. The workflow can preserve the portal context, investigator navigation, observed playback, authorized video exports, network information, hashes, timestamps, and custody records. Eviquire does not acquire directly from a camera, DVR, NVR, storage disk, proprietary desktop client, or vendor backend that is not exposed through the web interface.

CCTV portal evidence is more than the visible video. Camera identity, site or zone, portal account, selected date range, displayed timezone, playback controls, stream quality, event markers, export settings, and the relationship between observed playback and a downloaded file can all affect interpretation. Browser portals may use segmented or transcoded streams, dynamic timelines, short retention periods, proprietary export formats, or vendor-specific players, so the examiner must document both what the portal displayed and the limitations of the acquisition.

Common situations

When this workflow is useful

  • Preserving incident footage available through a cloud CCTV, VMS, building-security, retail, transport, or access-control web portal
  • Documenting how an authorized operator located, filtered, played, and exported footage for litigation, insurance, workplace, compliance, or criminal investigation
  • Capturing expiring or remotely hosted footage before the portal retention period, permissions, or available recordings change

Recommended process

A documented acquisition workflow

  1. Confirm authority, scope, and retention

    Document the legal or organizational authority, portal tenant, authorized account, relevant site and cameras, incident period, timezone, expected retention deadline, export permissions, and excluded areas before accessing footage.

  2. Validate browser compatibility and access

    Confirm that the target portal works through Eviquire’s integrated browser using the required network or VPN, SSO, MFA, proxy, client certificate, and supported video technology. A portal that requires a proprietary desktop client, unsupported browser plug-in, or direct recorder access may require another forensic method.

  3. Prepare the acquisition environment

    Create the case and acquisition record, identify the workstation, operating system, Eviquire version, investigator, portal URL, time source and timezone, network route, and required recording options. Verify Internet access for licensing and configured evidence-timestamping services.

  4. Establish the footage context

    Navigate from the portal entry point to the relevant organization, location, camera, event, date, and time interval. Preserve the camera label and identifier, portal filters, displayed timezone, playback speed, quality, overlays, and other settings that affect what is shown.

  5. Record and acquire the relevant playback

    Use acquisition-session video to document the search and playback sequence. Play the relevant interval at an appropriate quality and speed, record buffering or missing segments, and make targeted captures of important frames and surrounding portal information without presenting the session recording as the original camera file.

  6. Export the native portal artifact when available

    Use the portal’s authorized export or download function to preserve the available native or vendor-generated video, still image, report, metadata, or archive. Record the selected cameras, start and end times, export options, filename, format, and the investigator action that generated the file, then preserve its cryptographic hash.

  7. Verify, close, and transfer the case

    Check that the expected artifacts are present and playable with the appropriate authorized software, document failures or dependencies, close the case, verify integrity, and export it with the Portable Viewer or transfer it under the approved chain-of-custody procedure for independent review.

Technical guidance

Conditions that affect a CCTV portal acquisition

Validate the portal, video technology, time settings, export path, and evidential scope before the formal acquisition begins.

Browser-based scope

A practical suitability test is whether the authorized footage can be searched, played, and exported through a conventional standards-based web browser. Eviquire must be able to perform the relevant portal workflow through its integrated forensic browser.

  • Suitable: browser-accessible CCTV, VMS, cloud-camera, or security portals.
  • May be unsuitable: portals that depend on a proprietary thick client, unsupported legacy plug-in, hardware decoder, or direct DVR/NVR console.
  • Not a device acquisition: Eviquire does not image camera memory, recorder disks, or the surveillance backend.

Authentication and network access

Private portals can be reached through an authorized workstation and corporate VPN when Eviquire’s browser can satisfy the same routing, authentication, proxy, and certificate requirements. Test SSO, MFA, account permissions, and any IP or device restrictions before formal collection.

  • Use a specifically authorized account and record its role without exposing credentials.
  • Confirm access to both the CCTV portal and required Eviquire licensing or timestamping services.
  • Document VPN, proxy, certificate, region, and account conditions that could affect the available cameras or recordings.

Playback and acquisition-session video

The acquisition-session recording can show how the examiner selected the camera and time range, used the timeline, started playback, expanded the player, changed controls, and initiated an export. It is a continuous record of the portal interaction and observed playback.

  • Distinguish Eviquire’s session recording from the original or portal-exported CCTV file.
  • Record playback speed, quality, overlays, audio state, buffering, skipped intervals, and any investigator-controlled zoom or enhancement.
  • Avoid unnecessary transformations when the objective is to document what the portal originally presented.

Network recording

When Wireshark is installed and permitted, Eviquire can preserve packet-level traffic associated with the web acquisition. This may help document the portal endpoints and delivery activity, although encrypted traffic and segmented streaming can limit what packet inspection alone reveals. Without Wireshark, supported application-layer web and network-session context can still accompany the visible acquisition.

  • Eviquire with Wireshark: packet-level capture for the authorized session.
  • Eviquire without Wireshark: supported application-layer and web-session context.
  • Network capture does not by itself establish that a stream is the recorder’s original native file.

Exports, formats, and playback dependencies

A CCTV portal may export MP4, AVI, MOV, MKV, still images, ZIP archives, reports, metadata files, or a proprietary evidence package. Preserve the downloaded file exactly as supplied and retain any authorized vendor player, codec information, manifest, or verification instructions needed for later review.

  • Record the export’s camera selection, start and end times, timezone, quality, format, and filename.
  • Hash the original downloaded artifact before creating converted or working copies.
  • Clearly label transcoded, clipped, annotated, redacted, or converted derivatives and preserve the untouched export.

Time, camera identity, and corroboration

The portal may display time according to the camera, recorder, site, tenant, authenticated user, browser, or workstation configuration. Daylight-saving changes and clock drift can also affect interpretation. Preserve the displayed time and timezone and document the relevant portal settings when available.

  • Distinguish acquisition time, displayed footage time, and any export-file timestamps.
  • Record camera name, identifier, site or zone, and the navigation path that connected the footage to that camera.
  • Where event time or originality is disputed, correlate the portal acquisition with recorder audit logs, access logs, export logs, system configuration, or direct device evidence obtained under an appropriate method.

Reviewable output

What the evidence package should explain

Portal and camera context

The authenticated portal, URL, organization or site, camera identity, timeline, filters, playback controls, overlays, and navigation sequence explain where the footage was found.

Observed playback record

Acquisition-session video, screenshots, relevant frames, audio state, buffering notes, and playback settings document what the investigator observed through the portal.

Exported footage and integrity

Authorized video exports, stills, reports, metadata, or archives can be preserved in their supplied formats with hashes, timestamps, and the documented export action.

Technical and custody record

Environment details, supported network context, optional packet capture, acquisition history, case reports, integrity verification, and chain-of-custody records support later review.

The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.

Professional considerations

Authority, proportionality, and limitations

  • CCTV footage can contain highly sensitive personal data. Define authority, necessity, relevant cameras and time ranges, access controls, retention, disclosure, redaction, and secure transfer before collection.
  • A portal acquisition preserves what the authorized web system presented and exported; it does not independently prove that the footage is the recorder’s untouched original or that its displayed time is accurate.
  • Do not claim completeness when footage is missing, expired, overwritten, inaccessible, buffered, low quality, outside the selected interval, or unavailable because of permissions or portal limitations.
  • Preserve original portal exports unchanged. Perform clipping, conversion, enhancement, annotation, or redaction only on controlled derivatives while retaining their relationship to the original artifact.

Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.

Standards and primary guidance

Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.

Frequently asked questions

Can Eviquire acquire CCTV footage from a web portal?

Yes, when the authorized CCTV or video-management portal is accessible and operable through Eviquire’s integrated browser. Compatibility should be verified before the formal acquisition, particularly for portals using proprietary players or legacy plug-ins.

Is the Eviquire session recording the original CCTV video?

No. It documents what was displayed and what the investigator did during the portal session. When available and authorized, the portal’s native or vendor-generated export should also be preserved as a separate original artifact.

Can Eviquire acquire directly from a DVR or NVR?

No. Eviquire is a web-evidence acquisition product, not a hardware or storage-imaging tool. Direct recorder, camera, disk, or backend acquisition requires an appropriate surveillance-system or digital-forensic procedure.

What should be recorded about CCTV timestamps?

Record the displayed date and time, timezone, camera and site, selected interval, portal or user timezone settings, and any known clock offset or daylight-saving issue. Important times may need correlation with recorder or system logs.

What if the portal only provides a proprietary video format?

Preserve the original downloaded package exactly as supplied, hash it, and retain authorized information about the required vendor player, codec, manifest, or verification method. Create viewable derivatives only as documented working copies.

Is Wireshark required for a CCTV portal acquisition?

Wireshark is needed when packet-level network capture is required and permitted. Without it, Eviquire can still preserve the visible portal acquisition, session recording, downloaded artifacts, and supported application-layer web and network-session context.

Can another examiner review the acquired footage?

Yes. The closed case and preserved artifacts can be transferred under the approved procedure, reviewed through the Portable Viewer where applicable, or imported into another authorized Eviquire Desktop Expert installation. Proprietary CCTV exports may also require the vendor’s authorized player.

Does Eviquire prove that a CCTV recording is authentic?

Eviquire documents and protects the integrity of what was acquired through the portal. Authenticity conclusions may also require camera or recorder configuration, audit and export logs, direct system evidence, witness information, and examiner analysis.

Privacy preferences

Essential storage remembers this preference and is always active. Optional third-party services are disabled unless you allow them.