Preserve provenance, not just a screenshot
A useful evidence record identifies the original artifact, collector, collection method, data source and UTC time. Preserve raw responses as well as the human-readable interpretation. A screenshot can document appearance, but it does not replace message headers, DNS answers or response artifacts.
Public records change. A later lookup can differ from the data available when an incident occurred. Record observation time explicitly and avoid implying that a current DNS response describes historical conditions.
Integrity and handling
Calculate cryptographic hashes for preserved files and retain the hash values in a controlled evidence log. A hash helps detect changes to an artifact; it does not prove that the original content was accurate or that the collector followed proper procedure.
Maintain a chain-of-custody record describing possession, transfers, access and purpose. Apply access controls, retention rules and data minimization appropriate to the investigation. Legal admissibility depends on jurisdiction and circumstances, not on a report format alone.
Facts, inference and limitations
Clearly separate raw observations, analytical interpretation and unanswered questions. Avoid naming an operator solely from a registrar, shared hosting address or privacy proxy. Make every material conclusion traceable to supporting evidence.
- Save original artifacts and raw lookup responses.
- Record source, method, UTC collection time and collector.
- Hash preserved files and log handling events.
- Label facts, hypotheses and unavailable fields separately.
- State collection limitations and seek legal guidance where needed.
