Web-forensics use case

Acquire domain, DNS and hosting administration evidence

Eviquire can document authorized registrar, DNS, hosting, CDN and control-panel information presented through a browser, including domain and account context, nameservers, resource records, certificates, redirects, hosting configuration, administrative users, visible changes and billing or service records. Portal preservation should be correlated with live DNS, registry, certificate-transparency, server, provider audit or legal-process records when independent validation is required.

What this use case means

Eviquire can document authorized registrar, DNS, hosting, CDN and control-panel information presented through a browser, including domain and account context, nameservers, resource records, certificates, redirects, hosting configuration, administrative users, visible changes and billing or service records. Portal preservation should be correlated with live DNS, registry, certificate-transparency, server, provider audit or legal-process records when independent validation is required.

Infrastructure control panels expose live configuration that may change during incident response, propagate asynchronously or differ from public observations. Account screens can also reveal recovery information, API secrets and billing data. The acquisition must distinguish configured values from externally observed behaviour and avoid making operational changes.

Common situations

When this workflow is useful

  • Domain hijacking, phishing, outage, compromise, ownership, hosting or configuration disputes
  • Preserving infrastructure configuration before remediation or transfer
  • Documenting provider-side account and service presentation for incident, legal or compliance review

Recommended process

A documented acquisition workflow

  1. Define infrastructure scope

    List providers, accounts, domains, zones, records, services, dates and prohibited changes.

  2. Record authenticated context

    Preserve account role, tenant, service identifiers, MFA or SSO context, locale and navigation without exposing secrets.

  3. Acquire configuration and history

    Document domain status, contacts where authorized, nameservers, DNS records, certificates, redirects, users and available change events.

  4. Preserve authorized reports

    Download zone files, invoices, logs, configuration exports or certificates only when permitted and retain their supplied form.

  5. Correlate external state

    Hash artifacts and compare with registry, live and historical DNS, certificate transparency, server logs or provider records as needed.

Technical guidance

Conditions that affect infrastructure-portal evidence

Confirm these points during a short pre-acquisition validation on the authorized workstation.

Configured versus observed state

A control panel may show intended configuration while caches, propagation, proxy layers or stale records produce different external behaviour.

  • Record acquisition time precisely.
  • Preserve TTL and status where shown.
  • Correlate with independent observations.

Sensitive administration data

Panels may expose tokens, origin addresses, recovery contacts and payment information.

  • Collect narrowly.
  • Mask secrets only on derivatives.
  • Restrict original access.

Investigator effects

Editing, testing, regenerating or exporting can create changes and audit events.

  • Use read-only roles when possible.
  • Avoid save and rotate controls.
  • Document any unavoidable event.

Reviewable output

What the evidence package should explain

Account and service context

Provider, role, domain, zone, hosting or CDN service and navigation.

Configuration record

Nameservers, records, certificates, redirects, users and visible change state.

Supplied exports

Authorized zone, configuration, log, invoice or certificate files with hashes.

Correlated review package

Session record, external observations, timestamps, limitations and custody history.

The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.

Professional considerations

Authority, proportionality, and limitations

  • Infrastructure panels are security-critical; use least privilege and avoid exposing secrets or origin systems.
  • Portal values, public DNS and historical provider records are separate evidence sources.
  • Preserve state before authorized remediation, then document changes in a separate acquisition.

Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.

Standards and primary guidance

Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.

Frequently asked questions

Can Eviquire prove historical DNS configuration?

It can preserve visible history; independent historical DNS or provider records may be required.

Should DNS records be tested from the portal?

Avoid changes. External read-only observations should be documented separately.

Can certificate information be preserved?

Yes, together with the service and domain context; cryptographic validation remains separate.

Does a registrar account prove domain ownership?

It is relevant evidence but may require registry and contractual corroboration.

Can secrets be redacted?

Keep protected originals and create documented redacted review copies.

Privacy preferences

Essential storage remembers this preference and is always active. Optional third-party services are disabled unless you allow them.