Attaching Evidence
Upload files, screenshots, and logs to incident records.
During an incident response, collecting and preserving evidence is essential for understanding what happened, supporting regulatory notifications, and potentially assisting law enforcement investigations. CrownSync Playbooks allows you to attach files directly to incident timeline entries, creating a linked record of evidence alongside your response actions.
Uploading Files
You can attach evidence to any action entry in the incident timeline. To upload a file:
- Click Log Action or edit an existing timeline entry
- Click the Attach Evidence button (the paperclip icon)
- Select one or more files from your device
- Add an optional description for each file to explain its relevance
- Save the action entry
You can also drag and drop files directly onto the action form. Multiple files can be attached to a single timeline entry.
Supported File Formats
CrownSync accepts the following file types as evidence attachments:
- Images— PNG, JPEG, GIF, WebP, and SVG. Screenshots of error messages, phishing emails, and system states are among the most common evidence types.
- Documents— PDF, TXT, CSV, and JSON. Useful for log exports, configuration files, and formal correspondence.
- Spreadsheets— XLSX and CSV. Helpful for listing affected accounts, compromised records, or IP address logs.
- Log files— LOG, TXT, and CSV formats. System logs, firewall logs, and authentication logs are critical evidence.
- Email files— EML and MSG. Preserve the original phishing or malicious email with full headers intact.
- Archives— ZIP files for bundling multiple related evidence items.
Individual file size is limited to 25 MB. For larger files such as disk images or memory dumps, store them in your organisation's secure evidence repository and add a reference note to the timeline entry indicating where the evidence is held.
Evidence preservation
Once uploaded, evidence files cannot be modified or deleted. This preserves the chain of custody and ensures the integrity of the incident record. If you upload the wrong file, add a note to the timeline entry explaining the error and upload the correct file as a new attachment.
Evidence for Regulators
When notifying regulators such as the ICO or FCA, you may need to provide supporting evidence alongside your notification. CrownSync makes this straightforward:
- Evidence attached to timeline entries is included in incident reports as an appendix with file names, descriptions, and upload timestamps.
- The chronological association between actions and evidence demonstrates your response process to regulators.
- All evidence uploads are logged in the audit log, providing an immutable record of when evidence was collected and by whom.
Evidence Collection Best Practices
Follow these guidelines to ensure your evidence is useful and defensible:
- Capture early— Take screenshots and export logs before making changes to affected systems. Once you remediate, some evidence may be lost.
- Include context— When uploading a screenshot, add a description explaining what the image shows and why it is relevant. A screenshot without context has limited value.
- Preserve original files— Upload original files rather than copies where possible. For emails, save the original EML or MSG file rather than a screenshot.
- Record hash values— For critical evidence such as malware samples, note the SHA-256 hash in the description field for future reference.
- Do not upload malware— CrownSync is not a sandbox. If you need to preserve malware samples, store them in a dedicated malware analysis environment and reference the location in the timeline.
Storage and Security
Evidence files are stored securely with encryption at rest. Access to evidence is restricted to team members who have access to the associated incident. External collaborators cannot view evidence attachments unless explicitly granted access by an administrator. All access to evidence files is logged in the audit trail.
Was this page helpful?