Private digital intelligence bureau Lawful OSINT — Cyber monitoring — Due diligence
Evidence custodian creating verified copies of digital files in a controlled documentation studio

Method guide · 8 min

Preserve digital evidence without altering what matters.

During fraud, impersonation or sensitive publication, an immediate reaction can erase context. Simple, dated and reproducible preservation improves analysis and professional handover.

Published 15 September 2026Reviewed by IIS editorial team

At a glance

Four rules for a useful review.

  • Keep the original before editing.
  • Record date, time, time zone and context.
  • Log each copy and action.
  • Protect sensitive data and restrict access.

Step-by-step method

A reproducible path from question to conclusion.

  1. 1

    Stabilise the situation

    Secure threatened accounts and payments through official channels, but avoid deleting useful messages, logs or files before preserving them.

  2. 2

    Capture the context

    Save the full address, profile, publication, relevant comments, date and time. A screenshot without URL or context is fragile.

  3. 3

    Retain originals

    Keep emails in their original format, attachments intact and downloaded files without resaving them. Work from copies.

  4. 4

    Build a timeline

    Record what was observed, by whom and when, followed by actions and responses. Separate observation from interpretation.

  5. 5

    Transfer securely

    Share only what is necessary through an agreed channel. Never include passwords, temporary codes or complete identity documents in an initial message.

A screenshot is only one element

A screenshot shows what appeared on a screen but does not by itself prove authorship, integrity or origin. Add the URL, account, time, browsing context and original file where relevant.

For email, retain the exported message and headers. For a site, note the exact address and connected pages. For a conversation, preserve useful continuity without disclosing it to unrelated people.

Keep an understandable action trail

Name copies neutrally, retain an untouched version and log conversions. A file hash can support traceability, but does not replace context or the requirements of an authorised professional.

Store the case in a restricted, backed-up location separate from a potentially compromised system. Limit personal and sensitive data to what is needed.

Know when to hand over

Threats to a person, active compromise, extortion or fraudulent payment require prompt action by the appropriate services. OSINT may clarify public traces but cannot replace technical, judicial or medical response.

Where litigation is possible, ask counsel, an appropriate court officer or expert early about the suitable method of recording and transfer.

Common pitfalls

Four shortcuts that weaken the result.

Cropping the only copy

Always keep the complete original before annotating or obscuring data.

Renaming without a log

Simple version control preserves order and provenance.

Replying publicly

A response can amplify content, reveal strategy or cause deletion.

Sending everything

Useful collection stays targeted; over-collection exposes third parties.

Practical questions

Frequently asked questions.

Should every screenshot be printed?

No. The digital file, context and traceability are often essential. Printing may supplement but not replace the original.

Is a file hash enough?

No. It can show that a file has not changed since hashing, but does not alone prove its origin or truth.

How long should the file be retained?

That depends on the risk, applicable duties and possible proceedings. Keep it only as necessary and obtain tailored advice for legal matters.

Editorial scope

Written and reviewed by Internet Intelligence Service on 15 September 2026. This educational guide describes a lawful, defensive method. It is not legal advice, an emergency service or authority instruction.