Evidence data is described below for both the agent and target:
Data | Description | ||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Acquired |
Date-time evidence was acquired. It can be filtered. Last 24 hours is set by default. |
||||||||||||||||||
Received |
Date-time evidence was logged in RCS. It can be filtered. Last 24 hours is set by default. Tip: this data is helpful when you suspect that the target device's data-time is not updated and thus theAcquired is not valid. |
||||||||||||||||||
Relevance |
Level of evidence relevance, automatically assigned by alert rules or manually assigned in this list. The level of relevance is set using:
Short-cut key list.
|
||||||||||||||||||
Type |
Type of evidence to be selected. |
||||||||||||||||||
Info |
Evidence information: text, images, video, audio and so on. Each piece of information is accompanied by various fields (i.e.: field content, program). It can be filtered by simply indicating the full search word or full field name and search word. For example:
|
||||||||||||||||||
Notes |
Notes entered by the Analyst using:
|
||||||||||||||||||
Report |
Bookmark, that indicates that evidence may be included/excluded during export. The bookmark is set using:
|
||||||||||||||||||
Agent |
(only for target evidence) Name of the agent that logged the evidence. |