Web-forensics use case
Acquire evidence from cloud and security administration portals
Eviquire can document authorized evidence presented through cloud administration, identity, SIEM, EDR, security, incident, or audit web portals, including tenant context, dashboards, alerts, queries, filters, event detail, visible audit views, and browser-generated exports. It complements but does not replace cloud APIs, log-source preservation, snapshots, provider exports, SIEM retention, or endpoint forensics.
What this use case means
Eviquire can document authorized evidence presented through cloud administration, identity, SIEM, EDR, security, incident, or audit web portals, including tenant context, dashboards, alerts, queries, filters, event detail, visible audit views, and browser-generated exports. It complements but does not replace cloud APIs, log-source preservation, snapshots, provider exports, SIEM retention, or endpoint forensics.
Security consoles continuously update and often show aggregated, normalized, sampled, or retention-limited data. Queries, tenant scope, time range, timezone, role, and console defaults determine the result. A defensible capture must preserve those parameters and distinguish the displayed interpretation from raw logs and authoritative source records.
Common situations
When this workflow is useful
- Incident response, compromise, identity, fraud, compliance, audit, or internal investigation
- Preserving an alert, query result, administrative setting, incident timeline, or audit view before retention or state changes
- Documenting what an authorized analyst observed and how a console result was generated
Recommended process
A documented acquisition workflow
- Define technical scope
Identify tenant, subscription, account role, services, alerts, incidents, identities, queries, dates, and excluded systems.
- Record console state
Document portal URL, tenant and region, role, timezone, query language, filters, sort, pagination, retention, and network route.
- Acquire results and drill-down
Preserve overview, query, results, event or alert detail, linked entities, incident timeline, settings, and visible audit context.
- Export and correlate
Preserve authorized CSV, JSON, reports, or evidence exports, hash originals, record source limitations, and identify raw logs or APIs required for validation.
Technical guidance
Conditions that affect cloud and security-console acquisition
Confirm these points during a short pre-acquisition validation on the authorized workstation.
Live and derived data
Dashboards and alerts may update, normalize, deduplicate, enrich, or suppress events.
- Record exact time range and query.
- Capture result count and pagination.
- Document refreshes and changing status.
Privilege and side effects
Administrative portals can expose secrets and allow destructive or containment actions.
- Use read-only roles where possible.
- Never expose keys or tokens.
- Avoid remediation actions during collection.
Raw evidence and exports
Console results are not necessarily raw source logs.
- Preserve authorized exports with schema and parameters.
- Correlate with source logs, APIs, snapshots, and endpoint evidence.
- Record retention and ingestion limitations.
Reviewable output
What the evidence package should explain
Console context
Tenant, service, role, region, query, filters, timezone, and retention.
Security presentation
Dashboards, alerts, incidents, entities, events, audit views, and session activity.
Exports
Authorized CSV, JSON, reports, and related files with hashes.
Review package
Acquisition sequence, timestamps, limitations, reports, and custody records.
The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.
Professional considerations
Authority, proportionality, and limitations
- Security portals may expose credentials, secrets, personal data, and sensitive infrastructure; strictly minimize and restrict evidence.
- Do not treat a dashboard as the complete raw event record or a vendor alert as proof of compromise.
- Collection must not trigger containment, deletion, account changes, or other operational actions unless separately authorized.
Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.
Standards and primary guidance
Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.
Frequently asked questions
Can Eviquire preserve a SIEM or cloud-console result?
Yes, as presented through a compatible authorized web interface.
Does it acquire raw logs?
Not automatically. Preserve authorized exports and use log or API acquisition when raw data is required.
Why record the query and timezone?
They directly determine the returned events and their interpretation.
Can live dashboards change during capture?
Yes. Record refreshes, result changes, and acquisition sequence.
Should administrator credentials appear in evidence?
No. Never record passwords, tokens, keys, or unnecessary secrets.
Who uses this workflow?
Relevant professional roles
This acquisition workflow is commonly relevant to these teams. The appropriate authority, scope, procedure, and review requirements still depend on the matter.
Cyber-threat intelligence teams
Capture malicious infrastructure, actor content, web resources, downloads, and network context.
See role-specific guidance →Forensic experts
Acquire online evidence with technical context, integrity verification, custody records, and reporting.
See role-specific guidance →Law enforcement
Preserve volatile online evidence for authorized criminal and intelligence investigations.
See role-specific guidance →In-house legal teams
Preserve early evidence for disputes, compliance, legal holds, and outside-counsel review.
See role-specific guidance →