Eviquire use cases
Preserve online evidence for the work investigators actually do.
Each guide explains the collection objective, recommended workflow, useful evidence outputs, limitations, and questions reviewers commonly ask.
What can Eviquire be used for?
Eviquire supports documented acquisition of volatile online material from websites, social platforms, browser-accessible webmail, CRM and CCTV portals, video, authenticated pages, and dark-web sources. Depending on the selected workflow and configuration, an evidence package can contain visible content, source information, screenshots, session recording, network context, metadata, cryptographic hashes, timestamps, activity logs, chain-of-custody records, and forensic reports.
The software supports the collection process; it does not determine identity, truth, infringement, misconduct, or legal admissibility. Those conclusions require appropriate authority, corroborating evidence, validated procedures, and qualified human judgment.
Find workflows for your role
Which use cases are most relevant to you?
Choose your profession for a complete role-specific guide, or open one of the priority acquisition workflows directly.
Explore all profession-specific solutions →Browse by evidence source
Where does the online evidence appear?
Start with the kind of web interface, platform, or service that contains the material. Every link opens a detailed, canonical acquisition workflow.
Public websites and social media7 workflows
Pages, publications, profiles, posts, comments, claims, and other volatile public-facing material.
Video, email, and communications5 workflows
Online video, live streams, webmail, workplace chat, web meetings, and AI conversations.
Business applications and internal portals7 workflows
Authenticated systems used for customers, employees, support, commerce, finance, and operational records.
Cloud, document, and transaction portals5 workflows
Cloud files, virtual data rooms, signed transactions, learning systems, and project documentation.
Marketplaces, advertising, and intellectual property5 workflows
Listings, merchants, advertisements, brand use, protected works, registries, and platform activity.
Government and regulated portals6 workflows
Official, healthcare, insurance, financial, voting, utilities, and other regulated web interfaces.
Physical operations and location-based portals5 workflows
CCTV, access control, buildings, logistics, property, travel, and other interfaces connected to real-world operations.
Security, development, and internet infrastructure5 workflows
Threat sources, administration consoles, vulnerability findings, source-code portals, domains, DNS, and hosting.
Browse by investigative objective
What does the acquisition need to support?
Use the objective as a starting point, then select the workflow that matches the source and authorized scope of the matter.
Litigation, disputes, and legal preservation5 workflows
Preserve material before removal, disclosure, expert review, enforcement, or formal proceedings.
Fraud, impersonation, harassment, and abuse6 workflows
Document deceptive identities, harmful communications, marketplace activity, payment pathways, and online abuse.
Corporate and internal investigations7 workflows
Acquire authorized records from communications, customer, employee, support, accounting, and business systems.
Due diligence and commercial review7 workflows
Preserve documents, company claims, counterparties, transactions, properties, bookings, and registry records.
OSINT, public-interest, and intelligence work7 workflows
Preserve source-linked findings from public, social, video, advertising, infrastructure, and dark-web sources.
Cybersecurity and incident response6 workflows
Document hostile infrastructure, vulnerabilities, administration state, development history, and technical web context.
Regulatory, public-record, and compliance matters6 workflows
Acquire official or regulated records with careful attention to role, scope, time, and source limitations.
Events, multimedia, and operational reconstruction6 workflows
Reconstruct what was displayed or recorded across video, cameras, meetings, access systems, fleets, and project portals.
Explore by investigative task
45 detailed acquisition workflows
Website evidence for litigation
Website evidence preservation is the documented acquisition of relevant online content and its technical context before the material changes or disappears. For litigation, the objective is to create a reviewable record that can be authenticated and explained—not merely a screenshot of what was visible.
Social media evidence
Social media evidence acquisition preserves relevant posts, profiles, comments, media, and surrounding context in a documented session. A strong workflow records what was visible, where it appeared, how the investigator reached it, and how the resulting files can be checked later.
IP infringement evidence
Online intellectual-property evidence collection documents allegedly infringing listings, media, branding, claims, seller information, and transaction context before a platform or publisher changes the material. The capture should preserve both the disputed content and enough context to explain where and how it appeared.
OSINT evidence collection
OSINT evidence collection converts online research findings into preserved, attributable, and reviewable records. It connects an analyst’s observation to the source URL, collection time, navigation path, technical context, integrity information, and case rationale.
Video and streaming evidence
Online video evidence acquisition documents the media together with the webpage, account, title, description, visible date, URL, playback context, and collection history. The objective is to preserve what was available and observed without confusing a screen recording with the original media file.
Internal investigations
Online evidence in an internal investigation should be collected under a defined mandate, with attention to relevance, employee privacy, privilege, retention, and access. A documented acquisition can preserve external pages or authorized web-accessible material while recording who collected it, when, and how.
Authenticated web content
Authenticated web evidence acquisition documents content that is visible only after authorized login or through a restricted workflow. Because access state affects what the page displays, the report should explain the account context, navigation, permissions, and collection boundaries without exposing credentials.
Dark-web evidence
Dark-web evidence acquisition preserves relevant content from services that require specialized access while documenting source identifiers, access conditions, collection time, navigation, integrity information, and investigator actions. Operational security and legal authority are central to the workflow.
Online defamation evidence
Online defamation evidence collection preserves the alleged statement together with the publication context needed to review it later: the page or post, author or account as presented, URL, audience-facing context, date and time, linked material, and collection record. It documents what was available during acquisition; it does not decide whether a statement is defamatory or who is legally responsible.
Harassment and threat evidence
Online harassment and threat evidence collection documents reported posts, messages, profiles, media, and interaction context before it changes or disappears. The aim is a clear record of what was displayed and how it was acquired, while protecting sensitive information and avoiding unsupported conclusions about identity, intent, or risk.
Fraud and impersonation evidence
Online fraud and impersonation evidence collection documents websites, adverts, social accounts, listings, communications, and payment-facing material that may be relevant to a suspected scam or false identity. It preserves the presentation and collection record for review; it does not prove fraud, identify an operator, or replace financial, legal, or law-enforcement investigation.
Web-based CRM evidence
Eviquire Desktop Expert can support the forensic acquisition of records from a browser-accessible CRM, including a CRM reached through an authorized corporate workstation and VPN. The target must be operable through Eviquire’s integrated forensic browser; Eviquire is not an endpoint-imaging tool and does not acquire evidence directly from a proprietary Windows thick-client application.
CCTV web portal footage
Eviquire Desktop Expert can support the documented acquisition of CCTV footage presented through an authorized browser-accessible surveillance portal. The workflow can preserve the portal context, investigator navigation, observed playback, authorized video exports, network information, hashes, timestamps, and custody records. Eviquire does not acquire directly from a camera, DVR, NVR, storage disk, proprietary desktop client, or vendor backend that is not exposed through the web interface.
Webmail evidence acquisition
Eviquire Desktop Expert can support the documented acquisition of email evidence presented through an authorized browser-accessible webmail account. The workflow can preserve mailbox and folder context, messages and threads, visible addressing and time information, attachments, available message headers and native exports, investigator activity, hashes, timestamps, and custody records. It is not a mail-server acquisition tool and does not image mailbox databases, endpoint PST or OST files, or content that the authorized web interface does not expose.
Geographic bulk web acquisition
Eviquire supports documented bulk acquisition of a defined URL list through controlled Web or SOCKS proxy routes, including approved country-specific exits. Every URL discovered by the crawler can be acquired through all proxies configured in Eviquire for the acquisition. It can also collect multipage results from a search engine, portal, marketplace, or authorized dark-web shop and acquire each eligible linked result or product page individually.
Workplace chat evidence
Eviquire can document authorized content presented through a browser-accessible workplace chat or collaboration service, including workspace and channel context, direct messages, threads, reactions, shared files, meeting artifacts, available exports, and the investigator’s acquisition path. It does not replace provider eDiscovery, API, audit-log, retention, or endpoint acquisition when those underlying sources are required.
Cloud document portal evidence
Eviquire can preserve evidence displayed through an authorized cloud storage or document portal: folder paths, document previews, ownership and sharing information, comments, visible versions and activity, native downloads, and acquisition records. It does not replace provider API collection, cloud-native export, synchronized endpoint acquisition, or backend audit evidence.
Support ticket evidence
Eviquire can document authorized helpdesk and customer-support records presented through a browser, including ticket identity, customer and agent messages, internal notes, status and assignment history, attachments, linked records, SLA information, visible audit events, exports, and acquisition activity. It does not replace the service database, API, provider audit logs, or CRM backend.
Virtual data room evidence
Eviquire can document authorized content presented through a browser-based virtual data room, including room and folder structure, document identity, version and watermark presentation, permissions, Q&A, visible activity, controlled downloads, and acquisition records. It does not override view-only restrictions or replace provider audit, administrator export, API, or backend acquisition.
ERP and accounting portal evidence
Eviquire can document records presented through an authorized browser-based ERP, procurement, expense, inventory, or accounting application, including linked transactions, approvals, vendors, reports, visible audit history, attachments, and exports. It does not acquire the underlying database, accounting engine, integration logs, or endpoint files.
E-commerce portal evidence
Eviquire can document authorized records presented through an e-commerce, marketplace seller, payment-service, or merchant administration portal, including products, orders, customers, payment status, refunds, disputes, shipping, messages, reports, and exports. It does not replace processor, marketplace, database, API, or financial-institution records.
HR portal evidence
Eviquire can document narrowly scoped records presented through an authorized browser-based HR, recruitment, attendance, expense, learning, or employee-case portal. It preserves the web presentation and authorized exports with acquisition records; it does not replace the HR database, payroll engine, identity provider, endpoint, or provider backend.
Cloud security portal evidence
Eviquire can document authorized evidence presented through cloud administration, identity, SIEM, EDR, security, incident, or audit web portals, including tenant context, dashboards, alerts, queries, filters, event detail, visible audit views, and browser-generated exports. It complements but does not replace cloud APIs, log-source preservation, snapshots, provider exports, SIEM retention, or endpoint forensics.
Financial portal evidence
Eviquire can document authorized account and transaction information presented through browser-based banking, payment, wallet, exchange, or financial-service portals, including balances as displayed, transactions, counterparties, beneficiaries, statements, status histories, exchange activity, and authorized exports. It does not replace institution records, blockchain analysis, API collection, wallet acquisition, or formal disclosure from the provider.
Official portal evidence
Eviquire can document public or authorized content presented through browser-based government, regulatory, registry, licensing, tax, customs, procurement, or court portals, including references, filings, entries, notices, application histories, receipts, status, and downloadable documents. It preserves the web presentation but does not turn it into a certified official record or replace records obtained directly from the authority.
IoT and access-control portal evidence
Eviquire can document authorized alarm, access-control, sensor, device, and building-management information presented through a compatible web portal, including site and zone context, device identity, dashboards, event histories, status, users or badges as displayed, and authorized exports. It does not acquire controller memory, device firmware, physical media, raw telemetry stores, or the underlying access-control database.
Web vulnerability evidence
Eviquire can help an authorized security tester preserve the observable behaviour of a browser-accessible application, the steps used to reproduce a finding, acquisition-session video, relevant HTTP and network context, TLS information, downloaded artifacts, hashes, timestamps, and an auditable handoff package. It documents what the tested application presented; it does not independently prove the source-code defect, server compromise, business impact, or exploitability in every environment.
Digital-signature evidence
Eviquire can preserve an authorized digital-signature portal’s presentation of an envelope or transaction: participants, document version, consent and authentication screens, signing sequence, status history, audit trail, completion certificate, downloaded signed files, and the investigator’s acquisition record. This preserves what the service displayed and supplied; cryptographic signature validation and authoritative identity verification remain separate examinations.
Insurance claims evidence
Eviquire can document authorized insurance-claim information presented through a web portal, including claim and policy context, parties, status and assignment history, communications, adjuster notes where permitted, uploaded evidence, decisions, payment information and generated exports. It is not a direct acquisition of the insurer’s claims database, underwriting system, medical records or provider audit backend.
DevOps portal evidence
Eviquire can preserve authorized content presented by browser-based source-control and DevOps services: repository and organization context, commits, branches, pull requests, reviews, issues, releases, packages, CI/CD runs, deployment history, visible user activity and downloaded artifacts. It complements rather than replaces a native repository clone, API export, provider audit log, build-system record or endpoint acquisition.
Domain and hosting evidence
Eviquire can document authorized registrar, DNS, hosting, CDN and control-panel information presented through a browser, including domain and account context, nameservers, resource records, certificates, redirects, hosting configuration, administrative users, visible changes and billing or service records. Portal preservation should be correlated with live DNS, registry, certificate-transparency, server, provider audit or legal-process records when independent validation is required.
Web meeting evidence
Eviquire can preserve authorized information presented by a browser-accessible meeting platform: meeting identity and schedule, participant presentation, recordings, transcripts, chat, reactions, polls, shared files, attendance information and available exports. It records what the account could access; provider logs, host devices, native recording files and identity records may be required for a complete examination.
Online advertising evidence
Eviquire can document authorized advertising-account content presented through a browser, including account and campaign structure, advertisements and creatives, targeting settings, publication and review status, delivery metrics, billing context, change history and generated reports. It preserves the platform presentation at acquisition time; it does not independently prove who viewed an advertisement, why an algorithm delivered it, or the completeness of provider backend data.
Learning and examination evidence
Eviquire can preserve authorized records presented by a browser-based learning or examination portal, including enrolment, course and assessment context, submissions, attempt and grade presentation, feedback, communications, certificates and visible activity history. It is not a direct acquisition of the learning database, proctoring backend, student device or institution’s authoritative academic record.
Logistics and fleet evidence
Eviquire can preserve authorized logistics and fleet information presented through a browser: consignment identity, tracking events, dispatch and route context, vehicle or driver presentation, delivery confirmation, supporting documents and generated exports. Portal evidence should be distinguished from direct telematics, vehicle, warehouse, scanner, carrier backend or geospatial-system acquisition.
Healthcare portal evidence
Eviquire can preserve authorized information displayed through a healthcare or patient web portal, including patient and provider context, appointments, communications, prescriptions, test-result presentation, billing and downloadable documents. This is a narrowly scoped web-interface acquisition and is not a substitute for a certified health record, direct clinical-system export, imaging-system acquisition or provider audit evidence.
Property and tenancy evidence
Eviquire can document authorized evidence presented through property, tenancy and real-estate portals, including listings, applications, leases, maintenance requests, agent and tenant communications, payments, inspection or transaction documents and visible histories. It preserves the web presentation and supplied files, not the complete property-management database, land registry or authoritative signed contract repository.
Travel and booking evidence
Eviquire can preserve authorized travel and booking information presented through a browser, including reservation and itinerary context, passenger or guest presentation, modifications, payment and refund status, messages, loyalty activity and downloadable confirmations. It does not directly acquire airline, hotel, border, payment or booking-provider backend systems.
Online marketplace evidence
Eviquire can preserve public and authorized marketplace evidence including listings, seller and buyer profile presentation, orders, messages, reviews, disputes, account actions, platform decisions and supplied exports. The acquisition records what the platform displayed to the selected account and does not independently verify identity, ownership, payment settlement, inventory or provider backend events.
Gaming and gambling evidence
Eviquire can preserve authorized gaming or gambling account information presented through a browser, including account identity as displayed, purchases or deposits, wagers, game histories, communications, rewards, moderation actions and restrictions. It records the portal presentation and supplied exports; operator databases, payment systems, game servers, device evidence and jurisdictional records remain separate sources.
AI conversation evidence
Eviquire can preserve an authorized web-based AI or chatbot exchange together with the service and account context shown by the interface, model or mode label, prompts, responses, citations, attached files, conversation history, settings and available exports. It records a particular displayed exchange; it does not reveal hidden prompts, model weights, training data or guarantee that the same input will reproduce the same output.
Voting and survey portal evidence
Eviquire can document an authorized electronic voting, survey or consultation web interface: event and form identity, version, questions, permitted pre-submission selections, confirmation or receipt presentation, published results and authorized administrative views. It does not validate tallying algorithms, ballot secrecy, voter eligibility, backend databases or election infrastructure.
IP registry evidence
Eviquire can preserve patent, trademark, design and other intellectual-property registry information presented through a web portal, including application or registration identifiers, owners and representatives as displayed, classifications, status histories, filings, objections, renewals and official documents. It documents the portal presentation and downloaded records; formally certified extracts and authoritative registry data may still be required.
Construction project evidence
Eviquire can preserve authorized construction and project-management records presented through a browser, including project and package context, tasks, RFIs, submittals, approvals, change orders, drawings, document versions, site reports, communications and visible audit history. It complements rather than replaces the common data environment, native project export, signed contract record, endpoint or provider backend.
Utilities and telecom evidence
Eviquire can preserve authorized utility and telecommunications account information presented through a browser, including account and service context, configuration, usage, bills, outages, support interactions, orders, line or device information and downloadable statements. It records the customer or administrator portal presentation, not raw metering, network, switch, provider database or device evidence.
Applies to every use case
Evidence quality depends on method and judgment.
Appropriate authority
Confirm the legal or organizational basis, access permissions, scope, and collection boundaries before acquisition.
Relevant context
Preserve enough surrounding information to explain the source and meaning without collecting unrelated sensitive data.
Documented limitations
Record missing, inaccessible, dynamic, interrupted, or uncertain material rather than implying completeness.
Reviewable integrity
Use hashes, trustworthy time information, activity logs, custody records, and controlled handling so later changes can be detected.
Professional guidance
Organizations should validate their procedures and follow applicable law and policy. Useful primary references include SWGDE Best Practices for Acquiring Online Content, ISO/IEC 27037:2012, and NIST digital-evidence resources.
Need a direct answer?
Browse 72 web-forensics questions.
Find concise guidance on acquiring webpages, authenticated content, social media, video, technical context, integrity, and legal procedure.
Frequently asked questions
What are Eviquire use cases?
Eviquire use cases describe practical workflows for preserving websites, social media, video, authenticated pages, dark-web sources, and other volatile online material with context, integrity records, activity history, chain of custody, and reporting.
How are use cases different from industry solutions?
A use case starts with the task an investigator needs to complete, such as preserving a social post or documenting an online listing. A solution page starts with the professional audience, such as law enforcement, legal teams, or OSINT analysts.
Does Eviquire make online evidence automatically admissible?
No. Eviquire supports documented acquisition and verification. Courts and other decision-makers assess evidence under the facts, methods, and rules that apply in their jurisdiction.