Web-forensics use case

Preserve online harassment and threat evidence

Online harassment and threat evidence collection documents reported posts, messages, profiles, media, and interaction context before it changes or disappears. The aim is a clear record of what was displayed and how it was acquired, while protecting sensitive information and avoiding unsupported conclusions about identity, intent, or risk.

What this use case means

Online harassment and threat evidence collection documents reported posts, messages, profiles, media, and interaction context before it changes or disappears. The aim is a clear record of what was displayed and how it was acquired, while protecting sensitive information and avoiding unsupported conclusions about identity, intent, or risk.

Harmful content can be deleted quickly, sent through private or authenticated areas, copied between accounts, or embedded in a longer sequence of interactions. Isolated screenshots can lose the account context, message history, URL, timing, access conditions, and evidence of how the material was observed.

Common situations

When this workflow is useful

  • Reported cyberbullying, abusive posts, stalking-related communications, or online threats
  • Preserving visible public posts, comments, profiles, media, and authorized messages for an investigation
  • Preparing a documented record for safeguarding, legal, HR, platform, or law-enforcement review

Recommended process

A documented acquisition workflow

  1. Assess urgency and authority

    Follow the organization’s safety and escalation procedure first. Define the sources, account access, time window, lawful authority, and sensitive-data boundaries for collection.

  2. Preserve the relevant interaction

    Capture the reported content together with the account or profile presentation, URL, thread or conversation context, visible times, media, and platform information.

  3. Document access conditions

    Record whether the material was public or authenticated, the authorized account context, and any restrictions, missing messages, deleted items, or platform warnings.

  4. Protect the evidence package

    Retain original acquisition records, hashes, timestamps, activity logs, and chain-of-custody information while restricting access to sensitive content.

  5. Separate source material from assessment

    Report what was observed and any collection limitations. Keep safety assessment, attribution, and investigative conclusions clearly separate from captured evidence.

Reviewable output

What the evidence package should explain

Interaction context

Posts, messages, threads, profiles, URLs, visible times, and media show how the reported material appeared.

Authorized-session record

Screenshots, session video, activity history, and relevant technical context can document the acquisition process.

Integrity information

Hashes, timestamps, and custody records help detect changes to preserved artifacts after collection.

Controlled review package

Case organization and reporting support limited, need-to-know review without circulating sensitive content unnecessarily.

The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.

Professional considerations

Authority, proportionality, and limitations

  • If there is an immediate safety concern, follow emergency or safeguarding procedures; evidence collection should not delay appropriate escalation.
  • Do not attempt to identify, contact, confront, or interact with a person unless that action is explicitly authorized and part of a controlled procedure.
  • Private messages, child-safety information, and personal data may require specialist legal, welfare, privacy, and retention controls.

Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.

Standards and primary guidance

Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.

Frequently asked questions

What context should be captured with a threatening or abusive post?

Capture the post or message together with the relevant account or profile, URL or service location, thread or conversation context, visible date and time, media, and the authorized access conditions.

Can Eviquire identify who sent a message?

No. It records what a source displayed and how it was acquired. Attribution requires corroboration and appropriate investigative methods.

Should private messages be collected?

Only with appropriate authority and within a defined scope. Protect credentials and unrelated private material, and follow applicable safeguarding and privacy procedures.

Why keep a session record?

It can help a reviewer understand the sequence, access conditions, and context in which the material was observed, alongside the preserved artifacts.

Privacy preferences

Essential storage remembers this preference and is always active. Optional third-party services are disabled unless you allow them.