Evidence data

Evidence data is described below for both the agent and target:

Data Description

Acquired

Date-time evidence was acquired.

It can be filtered. Last 24 hours is set by default.

Received

Date-time evidence was logged in RCS.

It can be filtered. Last 24 hours is set by default.

Tip: this data is helpful when you suspect that the target device's data-time is not updated and thus theAcquired is not valid.

Relevance

Level of evidence relevance, automatically assigned by alert rules or manually assigned in this list. The level of relevance is set using:

  • the Relevance command in the menu
  • short-cut keys

Short-cut key list.

Icon Short-cut keys Description
ALT+4

Maximum relevance

ALT+3

Intermediate relevance

ALT+2

Normal relevance

ALT+1

Minimum relevance

- ALT+0

No relevance

Type

Type of evidence to be selected. See "List of types of evidence".

Info

Evidence information: text, images, video, audio and so on. Each piece of information is accompanied by various fields (i.e.: field content, program).

It can be filtered by simply indicating the full search word or

full field name and search word.

For example:

  • "boss" searches for the word "boss" or "Boss" in all fields
  • while "content:boss" searches for the word "boss" or "Boss" in content fields only.
Notes

Notes entered by the Analyst using:

  • Edit Note  menu
  • short-cut key ALT+N
Report

Bookmark, that indicates that evidence may be included/excluded during export.

The bookmark is set using:

  • Add Report menu
  • short-cut key ALT+R
Agent

(only for target evidence) Name of the agent that logged the evidence.