Web-forensics use case

Acquire evidence from IoT, access-control, and building portals

Eviquire can document authorized alarm, access-control, sensor, device, and building-management information presented through a compatible web portal, including site and zone context, device identity, dashboards, event histories, status, users or badges as displayed, and authorized exports. It does not acquire controller memory, device firmware, physical media, raw telemetry stores, or the underlying access-control database.

What this use case means

Eviquire can document authorized alarm, access-control, sensor, device, and building-management information presented through a compatible web portal, including site and zone context, device identity, dashboards, event histories, status, users or badges as displayed, and authorized exports. It does not acquire controller memory, device firmware, physical media, raw telemetry stores, or the underlying access-control database.

Operational portals aggregate live state and historical events from distributed controllers and sensors. Device clocks, gateway buffering, polling, timezone, user mappings, retention, alarm acknowledgement, and role permissions affect the presentation. The examiner must avoid operational controls while preserving site, zone, device, event, time, and export context.

Common situations

When this workflow is useful

  • Security, safety, workplace, insurance, facilities, access, environmental, or incident investigations
  • Preserving alarm, badge, door, sensor, device-status, or building events before retention or mappings change
  • Documenting what an authorized operator observed in a remote operational portal

Recommended process

A documented acquisition workflow

  1. Define operational scope

    Identify tenant, site, zones, devices, users or badges, event types, time range, and prohibited controls.

  2. Record environment

    Document portal, account role, timezone, site configuration, filters, network route, and visible device status.

  3. Acquire history safely

    Navigate from site and zone to device, event timeline, alarm or access detail, related user mapping, and dashboard without acknowledging or controlling systems.

  4. Export and correlate

    Preserve authorized event reports and files, hash originals, record retention and clock limitations, and identify controller or backend evidence needed for validation.

Technical guidance

Conditions that affect operational-portal acquisition

Confirm these points during a short pre-acquisition validation on the authorized workstation.

Live state and safety

Operational portals may allow door, alarm, HVAC, camera, or device control.

  • Use read-only access.
  • Do not acknowledge alarms or issue commands.
  • Coordinate with system owners and safety procedures.

Time and identity mapping

Device, gateway, server, site, and user timezones or clocks may differ; badge-to-person mappings can change.

  • Record the displayed timezone and identifiers.
  • Document known clock offsets.
  • Correlate disputed identity with authoritative access records.

Aggregated versus raw data

Dashboards and histories may summarize, poll, filter, or retain only part of raw telemetry.

  • Preserve filters and retention information.
  • Use backend or controller acquisition when raw evidence is required.
  • Record missing or offline devices.

Reviewable output

What the evidence package should explain

Operational context

Tenant, site, zone, device, account role, filters, timezone, and status.

Event presentation

Alarm, access, badge, sensor, user mapping, history, and session activity.

Reports and exports

Authorized event files and configuration views with hashes.

Review package

Acquisition sequence, time limitations, reports, integrity, and custody records.

The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.

Professional considerations

Authority, proportionality, and limitations

  • Operational systems can affect physical safety and security; collection must not control or disrupt them.
  • Portal presentation does not prove raw sensor accuracy, badge possession, device integrity, or backend completeness.
  • Access and sensor records may be highly sensitive personal or security data requiring strict protection.

Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.

Standards and primary guidance

Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.

Frequently asked questions

Can Eviquire acquire access-control events?

It can preserve selected events presented through a compatible authorized web portal.

Can it image a controller or IoT device?

No. Direct device, firmware, memory, and storage acquisition require specialized methods.

Can viewing an alarm change it?

It may; use read-only access and document any state change.

Why record site and timezone?

They are essential to interpret devices and event times correctly.

Are portal events raw telemetry?

Not necessarily. The interface may aggregate, filter, or summarize backend data.

Privacy preferences

Essential storage remembers this preference and is always active. Optional third-party services are disabled unless you allow them.