Evidence data is described below for both the agent and target:
Data | Description | ||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Acquisition |
Date-time evidence was acquired. It can be filtered. Last 24 hours is the default setting. |
||||||||||||||||||
Receipt |
Date-time evidence was logged in RCS. It can be filtered. Last 24 hours is the default setting. Tip: this data is helpful when you suspect that the target device's data-time is not updated and thus the Acquisition is not valid. |
||||||||||||||||||
Relevance |
Level of evidence relevance, automatically assigned by alert rules or manually assigned in this list. The level of relevance is set using:
Short-cut key list.
|
||||||||||||||||||
Type |
Type of evidence to be selected. See "List of types of evidence" |
||||||||||||||||||
Info |
Evidence information: text, images, video, audio and so on. All information is accompanied by different fields (i.e.: content, program fields). You can filter by simply indicating the word to be searched or the field name and word to be searched.
For example:
|
||||||||||||||||||
Notes |
Notes entered by the Analyst using:
|
||||||||||||||||||
Report |
Bookmark, that indicates that evidence may be included/excluded during export. The bookmark is set using:
|
||||||||||||||||||
Agent |
(only for target evidence) Name of the agent that logged the evidence. |
RCS9.5 | User manual | © COPYRIGHT 2014