Evidence data

Evidence data is described below for both the agent and target:

Data Description

Acquisition

Date-time evidence was acquired.

It can be filtered. Last 24 hours is the default setting.

Receipt

Date-time evidence was logged in RCS.

It can be filtered. Last 24 hours is the default setting.

Tip: this data is helpful when you suspect that the target device's data-time is not updated and thus the Acquisition is not valid.

Relevance

Level of evidence relevance, automatically assigned by alert rules or manually assigned in this list. The level of relevance is set using:

  • Relevance menu command
  • short-cut keys

Short-cut key list.

Icon Short-cut keys Description
Alt+4

Maximum relevance

Alt+3

Intermediate relevance

Alt+2

Normal relevance

Alt+1

Minimum relevance

- Alt+0

No relevance

Type

Type of evidence to be selected. See "List of types of evidence".

Info

Evidence information: text, images, video, audio and so on. All information is accompanied by different fields (i.e.: content, program fields).

You can filter by simply indicating the word to be searched or the field name and word to be searched.

 

For example:

  • "boss" searches for the word "boss" or "Boss" in all fields
  • while "content:boss" searches for the word "boss" or "Boss" in content fields only.
Notes

Notes entered by the Analyst using:

  • Edit Note menu
  • short-cut key Alt+N
Report

Bookmark, that indicates that evidence may be included/excluded during export.

The bookmark is set using:

  • Add report menu
  • short-cut key Alt+R
Agent

(only for target evidence) Name of the agent that logged the evidence.