Web-forensics use case
Preserve online harassment and threat evidence
Online harassment and threat evidence collection documents reported posts, messages, profiles, media, and interaction context before it changes or disappears. The aim is a clear record of what was displayed and how it was acquired, while protecting sensitive information and avoiding unsupported conclusions about identity, intent, or risk.
What this use case means
Online harassment and threat evidence collection documents reported posts, messages, profiles, media, and interaction context before it changes or disappears. The aim is a clear record of what was displayed and how it was acquired, while protecting sensitive information and avoiding unsupported conclusions about identity, intent, or risk.
Harmful content can be deleted quickly, sent through private or authenticated areas, copied between accounts, or embedded in a longer sequence of interactions. Isolated screenshots can lose the account context, message history, URL, timing, access conditions, and evidence of how the material was observed.
Common situations
When this workflow is useful
- Reported cyberbullying, abusive posts, stalking-related communications, or online threats
- Preserving visible public posts, comments, profiles, media, and authorized messages for an investigation
- Preparing a documented record for safeguarding, legal, HR, platform, or law-enforcement review
Recommended process
A documented acquisition workflow
- Assess urgency and authority
Follow the organization’s safety and escalation procedure first. Define the sources, account access, time window, lawful authority, and sensitive-data boundaries for collection.
- Preserve the relevant interaction
Capture the reported content together with the account or profile presentation, URL, thread or conversation context, visible times, media, and platform information.
- Document access conditions
Record whether the material was public or authenticated, the authorized account context, and any restrictions, missing messages, deleted items, or platform warnings.
- Protect the evidence package
Retain original acquisition records, hashes, timestamps, activity logs, and chain-of-custody information while restricting access to sensitive content.
- Separate source material from assessment
Report what was observed and any collection limitations. Keep safety assessment, attribution, and investigative conclusions clearly separate from captured evidence.
Reviewable output
What the evidence package should explain
Interaction context
Posts, messages, threads, profiles, URLs, visible times, and media show how the reported material appeared.
Authorized-session record
Screenshots, session video, activity history, and relevant technical context can document the acquisition process.
Integrity information
Hashes, timestamps, and custody records help detect changes to preserved artifacts after collection.
Controlled review package
Case organization and reporting support limited, need-to-know review without circulating sensitive content unnecessarily.
The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.
Professional considerations
Authority, proportionality, and limitations
- If there is an immediate safety concern, follow emergency or safeguarding procedures; evidence collection should not delay appropriate escalation.
- Do not attempt to identify, contact, confront, or interact with a person unless that action is explicitly authorized and part of a controlled procedure.
- Private messages, child-safety information, and personal data may require specialist legal, welfare, privacy, and retention controls.
Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.
Standards and primary guidance
Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.
Frequently asked questions
What context should be captured with a threatening or abusive post?
Capture the post or message together with the relevant account or profile, URL or service location, thread or conversation context, visible date and time, media, and the authorized access conditions.
Can Eviquire identify who sent a message?
No. It records what a source displayed and how it was acquired. Attribution requires corroboration and appropriate investigative methods.
Should private messages be collected?
Only with appropriate authority and within a defined scope. Protect credentials and unrelated private material, and follow applicable safeguarding and privacy procedures.
Why keep a session record?
It can help a reviewer understand the sequence, access conditions, and context in which the material was observed, alongside the preserved artifacts.