Forensic web acquisition
Why Eviquire is not a browser extension.
Browser extensions can be useful for routine capture. Eviquire is designed for a different task: documented web-evidence acquisition in a controlled environment, with the technical context needed for later review.
Convenient capture is not the same as documented acquisition.
A browser extension may save visible content or take a screenshot. In an investigation, the examiner may also need to explain the acquisition conditions, relevant technical exchanges, operator activity, integrity records, and how the result can be independently reviewed. Eviquire brings those elements into one dedicated web-forensics workflow.
Controlled environment
Acquire evidence outside an everyday browser profile.
Browser-extension capture
An extension runs inside the user’s general-purpose browser environment. That environment can include other extensions, custom settings, proxy configuration, cached content, injected scripts, and tools that affect how a page behaves or appears.
Eviquire acquisition
Eviquire provides a dedicated web-forensics acquisition environment. It is designed to retain relevant acquisition settings, activity, technical context, and evidence artifacts for later review rather than relying solely on content rendered in a normal browser profile.
Browser context
Other extensions can affect the result.
Extensions share a browser context with the page and with other installed extensions. Depending on permissions and behavior, other extensions can modify page content, inject scripts, block resources, change requests, or alter how information is displayed before a collection extension records it.
That does not make every extension unreliable, and extensions can be valuable for research, triage, bookmarking, or routine operational capture. In a forensic workflow, however, the acquisition environment should be documented and potential sources of alteration should be assessed.
Core acquisition context
Record the session and the technical exchanges.
Acquisition-session video recording
Eviquire can record the acquisition session, including browser or application-window activity and synchronized cursor and click indicators where applicable. This provides a reviewable record of what was displayed and what the operator did while collecting the evidence.
Network-traffic capture
Eviquire can capture relevant network traffic and technical context during an acquisition, including HTTP requests and responses, headers, downloaded resources, URLs, and related signals. This can help an examiner understand how material was delivered and identify supporting technical evidence.
Interception context
Help identify signs of man-in-the-middle interference.
A man-in-the-middle attack or interception proxy can alter content before it reaches the browser. An extension that records the rendered result may capture altered content without independently documenting the network path, traffic, or certificate context that could help an examiner identify the issue.
By capturing relevant traffic and certificate information during acquisition, Eviquire can help highlight indicators that require investigation, including unexpected TLS certificates or local man-in-the-middle proxy behavior. This gives an examiner additional technical context to assess whether content could have been modified in transit before acquisition.
Evidence artifacts
More than an image of a page.
Available artifacts depend on the source, workflow, configuration, plan, permissions, and operating environment.
Eviquire supports a repeatable process; it does not guarantee admissibility.
No software can guarantee that evidence will be accepted by a court or other decision-maker. Admissibility and evidential weight depend on the applicable law, facts, authority, procedure, examiner testimony, and how the evidence was handled. Investigators remain responsible for appropriate legal authority, validated procedures, and policies relevant to their case.
Continue your evaluation
Explore the acquisition capabilities in detail.
Review the feature library, see a product demonstration, or download Eviquire to evaluate the workflow in your environment.
Frequently asked questions
Can I use a browser extension and Eviquire together?
Yes. A browser extension may support research or early identification of relevant content. When content needs to be preserved for review, Eviquire can be used to perform and document the acquisition.
Are screenshots still included in an Eviquire acquisition?
Yes. Screenshots and full-page captures can be useful evidence artifacts. Eviquire treats them as part of a wider documented evidence package rather than the complete record.
Why is network traffic important in web forensics?
Network traffic can document relevant exchanges between the acquisition environment and the source, including requests, responses, headers, and downloaded resources. This can provide technical context that is not visible in a screenshot or rendered page alone.
Can network and certificate capture detect every man-in-the-middle attack?
No. Network and certificate capture can help identify indicators that need investigation, such as unexpected certificates or interception-proxy behavior, but cannot guarantee detection of every interception method or prove malicious tampering on its own.
Does Eviquire guarantee admissibility?
No software can guarantee admissibility. Evidential weight and admissibility depend on the applicable law, facts, authority, procedure, and how the evidence is handled.