Web-forensics use case
Acquire evidence from IoT, access-control, and building portals
Eviquire can document authorized alarm, access-control, sensor, device, and building-management information presented through a compatible web portal, including site and zone context, device identity, dashboards, event histories, status, users or badges as displayed, and authorized exports. It does not acquire controller memory, device firmware, physical media, raw telemetry stores, or the underlying access-control database.
What this use case means
Eviquire can document authorized alarm, access-control, sensor, device, and building-management information presented through a compatible web portal, including site and zone context, device identity, dashboards, event histories, status, users or badges as displayed, and authorized exports. It does not acquire controller memory, device firmware, physical media, raw telemetry stores, or the underlying access-control database.
Operational portals aggregate live state and historical events from distributed controllers and sensors. Device clocks, gateway buffering, polling, timezone, user mappings, retention, alarm acknowledgement, and role permissions affect the presentation. The examiner must avoid operational controls while preserving site, zone, device, event, time, and export context.
Common situations
When this workflow is useful
- Security, safety, workplace, insurance, facilities, access, environmental, or incident investigations
- Preserving alarm, badge, door, sensor, device-status, or building events before retention or mappings change
- Documenting what an authorized operator observed in a remote operational portal
Recommended process
A documented acquisition workflow
- Define operational scope
Identify tenant, site, zones, devices, users or badges, event types, time range, and prohibited controls.
- Record environment
Document portal, account role, timezone, site configuration, filters, network route, and visible device status.
- Acquire history safely
Navigate from site and zone to device, event timeline, alarm or access detail, related user mapping, and dashboard without acknowledging or controlling systems.
- Export and correlate
Preserve authorized event reports and files, hash originals, record retention and clock limitations, and identify controller or backend evidence needed for validation.
Technical guidance
Conditions that affect operational-portal acquisition
Confirm these points during a short pre-acquisition validation on the authorized workstation.
Live state and safety
Operational portals may allow door, alarm, HVAC, camera, or device control.
- Use read-only access.
- Do not acknowledge alarms or issue commands.
- Coordinate with system owners and safety procedures.
Time and identity mapping
Device, gateway, server, site, and user timezones or clocks may differ; badge-to-person mappings can change.
- Record the displayed timezone and identifiers.
- Document known clock offsets.
- Correlate disputed identity with authoritative access records.
Aggregated versus raw data
Dashboards and histories may summarize, poll, filter, or retain only part of raw telemetry.
- Preserve filters and retention information.
- Use backend or controller acquisition when raw evidence is required.
- Record missing or offline devices.
Reviewable output
What the evidence package should explain
Operational context
Tenant, site, zone, device, account role, filters, timezone, and status.
Event presentation
Alarm, access, badge, sensor, user mapping, history, and session activity.
Reports and exports
Authorized event files and configuration views with hashes.
Review package
Acquisition sequence, time limitations, reports, integrity, and custody records.
The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.
Professional considerations
Authority, proportionality, and limitations
- Operational systems can affect physical safety and security; collection must not control or disrupt them.
- Portal presentation does not prove raw sensor accuracy, badge possession, device integrity, or backend completeness.
- Access and sensor records may be highly sensitive personal or security data requiring strict protection.
Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.
Standards and primary guidance
Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.
Frequently asked questions
Can Eviquire acquire access-control events?
It can preserve selected events presented through a compatible authorized web portal.
Can it image a controller or IoT device?
No. Direct device, firmware, memory, and storage acquisition require specialized methods.
Can viewing an alarm change it?
It may; use read-only access and document any state change.
Why record site and timezone?
They are essential to interpret devices and event times correctly.
Are portal events raw telemetry?
Not necessarily. The interface may aggregate, filter, or summarize backend data.
Who uses this workflow?
Relevant professional roles
This acquisition workflow is commonly relevant to these teams. The appropriate authority, scope, procedure, and review requirements still depend on the matter.
Forensic experts
Acquire online evidence with technical context, integrity verification, custody records, and reporting.
See role-specific guidance →Law enforcement
Preserve volatile online evidence for authorized criminal and intelligence investigations.
See role-specific guidance →In-house legal teams
Preserve early evidence for disputes, compliance, legal holds, and outside-counsel review.
See role-specific guidance →Private investigators
Turn online findings into organized, verifiable evidence and professional client reports.
See role-specific guidance →