Step-by-step method
A reproducible path from question to conclusion.
- 1
Stabilise the situation
Secure threatened accounts and payments through official channels, but avoid deleting useful messages, logs or files before preserving them.
- 2
Capture the context
Save the full address, profile, publication, relevant comments, date and time. A screenshot without URL or context is fragile.
- 3
Retain originals
Keep emails in their original format, attachments intact and downloaded files without resaving them. Work from copies.
- 4
Build a timeline
Record what was observed, by whom and when, followed by actions and responses. Separate observation from interpretation.
- 5
Transfer securely
Share only what is necessary through an agreed channel. Never include passwords, temporary codes or complete identity documents in an initial message.
A screenshot is only one element
A screenshot shows what appeared on a screen but does not by itself prove authorship, integrity or origin. Add the URL, account, time, browsing context and original file where relevant.
For email, retain the exported message and headers. For a site, note the exact address and connected pages. For a conversation, preserve useful continuity without disclosing it to unrelated people.
Keep an understandable action trail
Name copies neutrally, retain an untouched version and log conversions. A file hash can support traceability, but does not replace context or the requirements of an authorised professional.
Store the case in a restricted, backed-up location separate from a potentially compromised system. Limit personal and sensitive data to what is needed.
Know when to hand over
Threats to a person, active compromise, extortion or fraudulent payment require prompt action by the appropriate services. OSINT may clarify public traces but cannot replace technical, judicial or medical response.
Where litigation is possible, ask counsel, an appropriate court officer or expert early about the suitable method of recording and transfer.
Common pitfalls
Four shortcuts that weaken the result.
Cropping the only copy
Always keep the complete original before annotating or obscuring data.
Renaming without a log
Simple version control preserves order and provenance.
Replying publicly
A response can amplify content, reveal strategy or cause deletion.
Sending everything
Useful collection stays targeted; over-collection exposes third parties.
Practical questions
Frequently asked questions.
Should every screenshot be printed?
No. The digital file, context and traceability are often essential. Printing may supplement but not replace the original.
Is a file hash enough?
No. It can show that a file has not changed since hashing, but does not alone prove its origin or truth.
How long should the file be retained?
That depends on the risk, applicable duties and possible proceedings. Keep it only as necessary and obtain tailored advice for legal matters.
Editorial scope
Written and reviewed by Internet Intelligence Service on 15 September 2026. This educational guide describes a lawful, defensive method. It is not legal advice, an emergency service or authority instruction.
