Web-forensics use case

Acquire evidence from cloud and security administration portals

Eviquire can document authorized evidence presented through cloud administration, identity, SIEM, EDR, security, incident, or audit web portals, including tenant context, dashboards, alerts, queries, filters, event detail, visible audit views, and browser-generated exports. It complements but does not replace cloud APIs, log-source preservation, snapshots, provider exports, SIEM retention, or endpoint forensics.

What this use case means

Eviquire can document authorized evidence presented through cloud administration, identity, SIEM, EDR, security, incident, or audit web portals, including tenant context, dashboards, alerts, queries, filters, event detail, visible audit views, and browser-generated exports. It complements but does not replace cloud APIs, log-source preservation, snapshots, provider exports, SIEM retention, or endpoint forensics.

Security consoles continuously update and often show aggregated, normalized, sampled, or retention-limited data. Queries, tenant scope, time range, timezone, role, and console defaults determine the result. A defensible capture must preserve those parameters and distinguish the displayed interpretation from raw logs and authoritative source records.

Common situations

When this workflow is useful

  • Incident response, compromise, identity, fraud, compliance, audit, or internal investigation
  • Preserving an alert, query result, administrative setting, incident timeline, or audit view before retention or state changes
  • Documenting what an authorized analyst observed and how a console result was generated

Recommended process

A documented acquisition workflow

  1. Define technical scope

    Identify tenant, subscription, account role, services, alerts, incidents, identities, queries, dates, and excluded systems.

  2. Record console state

    Document portal URL, tenant and region, role, timezone, query language, filters, sort, pagination, retention, and network route.

  3. Acquire results and drill-down

    Preserve overview, query, results, event or alert detail, linked entities, incident timeline, settings, and visible audit context.

  4. Export and correlate

    Preserve authorized CSV, JSON, reports, or evidence exports, hash originals, record source limitations, and identify raw logs or APIs required for validation.

Technical guidance

Conditions that affect cloud and security-console acquisition

Confirm these points during a short pre-acquisition validation on the authorized workstation.

Live and derived data

Dashboards and alerts may update, normalize, deduplicate, enrich, or suppress events.

  • Record exact time range and query.
  • Capture result count and pagination.
  • Document refreshes and changing status.

Privilege and side effects

Administrative portals can expose secrets and allow destructive or containment actions.

  • Use read-only roles where possible.
  • Never expose keys or tokens.
  • Avoid remediation actions during collection.

Raw evidence and exports

Console results are not necessarily raw source logs.

  • Preserve authorized exports with schema and parameters.
  • Correlate with source logs, APIs, snapshots, and endpoint evidence.
  • Record retention and ingestion limitations.

Reviewable output

What the evidence package should explain

Console context

Tenant, service, role, region, query, filters, timezone, and retention.

Security presentation

Dashboards, alerts, incidents, entities, events, audit views, and session activity.

Exports

Authorized CSV, JSON, reports, and related files with hashes.

Review package

Acquisition sequence, timestamps, limitations, reports, and custody records.

The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.

Professional considerations

Authority, proportionality, and limitations

  • Security portals may expose credentials, secrets, personal data, and sensitive infrastructure; strictly minimize and restrict evidence.
  • Do not treat a dashboard as the complete raw event record or a vendor alert as proof of compromise.
  • Collection must not trigger containment, deletion, account changes, or other operational actions unless separately authorized.

Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.

Standards and primary guidance

Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.

Frequently asked questions

Can Eviquire preserve a SIEM or cloud-console result?

Yes, as presented through a compatible authorized web interface.

Does it acquire raw logs?

Not automatically. Preserve authorized exports and use log or API acquisition when raw data is required.

Why record the query and timezone?

They directly determine the returned events and their interpretation.

Can live dashboards change during capture?

Yes. Record refreshes, result changes, and acquisition sequence.

Should administrator credentials appear in evidence?

No. Never record passwords, tokens, keys, or unnecessary secrets.

Privacy preferences

Essential storage remembers this preference and is always active. Optional third-party services are disabled unless you allow them.