Web-forensics use case
Acquire domain, DNS and hosting administration evidence
Eviquire can document authorized registrar, DNS, hosting, CDN and control-panel information presented through a browser, including domain and account context, nameservers, resource records, certificates, redirects, hosting configuration, administrative users, visible changes and billing or service records. Portal preservation should be correlated with live DNS, registry, certificate-transparency, server, provider audit or legal-process records when independent validation is required.
What this use case means
Eviquire can document authorized registrar, DNS, hosting, CDN and control-panel information presented through a browser, including domain and account context, nameservers, resource records, certificates, redirects, hosting configuration, administrative users, visible changes and billing or service records. Portal preservation should be correlated with live DNS, registry, certificate-transparency, server, provider audit or legal-process records when independent validation is required.
Infrastructure control panels expose live configuration that may change during incident response, propagate asynchronously or differ from public observations. Account screens can also reveal recovery information, API secrets and billing data. The acquisition must distinguish configured values from externally observed behaviour and avoid making operational changes.
Common situations
When this workflow is useful
- Domain hijacking, phishing, outage, compromise, ownership, hosting or configuration disputes
- Preserving infrastructure configuration before remediation or transfer
- Documenting provider-side account and service presentation for incident, legal or compliance review
Recommended process
A documented acquisition workflow
- Define infrastructure scope
List providers, accounts, domains, zones, records, services, dates and prohibited changes.
- Record authenticated context
Preserve account role, tenant, service identifiers, MFA or SSO context, locale and navigation without exposing secrets.
- Acquire configuration and history
Document domain status, contacts where authorized, nameservers, DNS records, certificates, redirects, users and available change events.
- Preserve authorized reports
Download zone files, invoices, logs, configuration exports or certificates only when permitted and retain their supplied form.
- Correlate external state
Hash artifacts and compare with registry, live and historical DNS, certificate transparency, server logs or provider records as needed.
Technical guidance
Conditions that affect infrastructure-portal evidence
Confirm these points during a short pre-acquisition validation on the authorized workstation.
Configured versus observed state
A control panel may show intended configuration while caches, propagation, proxy layers or stale records produce different external behaviour.
- Record acquisition time precisely.
- Preserve TTL and status where shown.
- Correlate with independent observations.
Sensitive administration data
Panels may expose tokens, origin addresses, recovery contacts and payment information.
- Collect narrowly.
- Mask secrets only on derivatives.
- Restrict original access.
Investigator effects
Editing, testing, regenerating or exporting can create changes and audit events.
- Use read-only roles when possible.
- Avoid save and rotate controls.
- Document any unavoidable event.
Reviewable output
What the evidence package should explain
Account and service context
Provider, role, domain, zone, hosting or CDN service and navigation.
Configuration record
Nameservers, records, certificates, redirects, users and visible change state.
Supplied exports
Authorized zone, configuration, log, invoice or certificate files with hashes.
Correlated review package
Session record, external observations, timestamps, limitations and custody history.
The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.
Professional considerations
Authority, proportionality, and limitations
- Infrastructure panels are security-critical; use least privilege and avoid exposing secrets or origin systems.
- Portal values, public DNS and historical provider records are separate evidence sources.
- Preserve state before authorized remediation, then document changes in a separate acquisition.
Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.
Standards and primary guidance
Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.
Frequently asked questions
Can Eviquire prove historical DNS configuration?
It can preserve visible history; independent historical DNS or provider records may be required.
Should DNS records be tested from the portal?
Avoid changes. External read-only observations should be documented separately.
Can certificate information be preserved?
Yes, together with the service and domain context; cryptographic validation remains separate.
Does a registrar account prove domain ownership?
It is relevant evidence but may require registry and contractual corroboration.
Can secrets be redacted?
Keep protected originals and create documented redacted review copies.
Who uses this workflow?
Relevant professional roles
This acquisition workflow is commonly relevant to these teams. The appropriate authority, scope, procedure, and review requirements still depend on the matter.
OSINT analysts
Connect volatile online findings to their sources, time, collection method, and integrity records.
See role-specific guidance →Cyber-threat intelligence teams
Capture malicious infrastructure, actor content, web resources, downloads, and network context.
See role-specific guidance →Forensic experts
Acquire online evidence with technical context, integrity verification, custody records, and reporting.
See role-specific guidance →Law enforcement
Preserve volatile online evidence for authorized criminal and intelligence investigations.
See role-specific guidance →