Incident Investigation & Evidence Collection

Anexet's Investigations module lets security teams build a structured, court-ready evidence case directly from intercepted data — emails, messenger conversations, file transfers, screenshots, and screen recordings — without leaving the Client Console. Available on the Premium plan.

Schedule a Demo
Anexet Client Console showing an open investigation case with pinned evidence items

From Scattered Alerts to a Structured Case

When a DLP alert fires, the data is rarely the problem — organizing it into defensible evidence is.

When a DLP alert fires or an HR matter escalates, security teams rarely lack data — they lack a way to organize it. Evidence sits scattered across different channels: an email thread here, a USB transfer log there, a screen recording in another module. Correlating everything manually wastes hours and risks losing the chain of custody the legal or compliance team will need later.

The Investigations module in Anexet's Client Console solves exactly that. It gives the analyst a dedicated workspace to pull intercepted evidence across every monitored channel — email, messengers, web, cloud storage, file operations, audio/video recordings — and build a structured case from a single interface. The case file accumulates automatically as the analyst pins relevant intercepts, and the resulting evidence package meets the evidentiary standards used in legal and disciplinary proceedings.

Because Anexet is deployed entirely on-premise, every piece of intercepted content — including the case file itself — stays within your organization's infrastructure. No data passes through vendor servers. That separation is a structural feature, not a policy: the vendor has no technical pathway to your evidence.

Why it matters

  • All channels, one workspace

    Email, messengers, file transfers, recordings, and clipboard events — every monitored channel feeds into one structured case file.

  • Chain of custody preserved

    Every pinned item retains its original timestamp, user account, channel, and interception parameters — ready for legal or disciplinary proceedings.

  • On-premise, no vendor access

    Anexet is deployed on your servers; the vendor has no technical pathway to intercepted content or case files.

Evidence Sources Available in an Investigation

All of the following feed directly into the Investigations workspace. Each item carries a verified timestamp, the local user account, and the interception channel. The Investigations module is available on the Premium plan.

Communication channels

  • Email (POP3, SMTP, IMAP, MAPI, Exchange, M365)

    Premium

    Full message content, attachments, and headers.

  • Desktop and web messengers

    Premium

    WhatsApp, Telegram, Teams, Slack, Viber, Discord, Signal, and 20+ more — full conversation threads, attached files, call metadata.

  • Speech-to-text transcripts

    Premium

    Intercepted voice communications transcribed and fully searchable in the Console.

Endpoint activity

  • File operations audit

    Premium

    Create, copy, move, rename, and delete on workstations and network shares.

  • File transfers

    Premium

    USB, cloud storage (desktop and web), FTP, and network shares — content intercepted and linked to the user.

  • Screenshots and screen recordings

    Premium

    Captured at any moment and on schedule — timestamped and user-attributed.

  • Clipboard events

    Premium

    Content copied and the application context at the time of the event.

  • Keylogger log

    Premium

    Typed input tied to the active window.

  • Webcam snapshots

    Premium

    User-attributed and timestamped still images from the endpoint camera.

  • Audio and video recordings

    Premium

    Screen, microphone, webcam, and speakers — indexed by session with an activity journal for fast navigation.

Analytics & context

  • Image recognition output

    Premium

    Text recognized from intercepted images and documents, including stamps and seals — fully searchable.

  • User relations graph

    Premium

    Visual map of who communicated with whom, across which channels, and when.

  • Risk Analysis score history

    Premium

    Behavioral anomaly timeline showing when the user's risk score spiked relative to the incident date.

The Investigations module is exclusive to the Premium plan. Our team confirms the full evidence matrix for your environment during the demo.

What Anexet Captures for an Investigation

The Investigations module draws on every channel Anexet monitors at the endpoint — email, messengers, file transfers, screen recordings, clipboard events, keylogger logs, and webcam snapshots. Each intercepted item carries a verified timestamp, the local user account, and the interception channel, so the analyst can pin it to a case with full context intact.

Because Anexet is deployed on-premise, the vendor has no access to your data. All intercepted evidence, case files, annotations, and exported reports remain on your organization's own servers throughout the investigation lifecycle — a structural guarantee, not just a policy.

Intercepted evidence items listed in the Anexet Investigations workspace
User activity timeline showing behavioral context linked to an open investigation

How an Investigation Works — 4 Steps

From the first alert to an exportable evidence package, the entire workflow stays inside the Client Console.

Trigger or search — start from a policy alert, a tip, or a proactive search using Information Search, Complex Search, or the User Activity profile.

1

Build the case — create a named case, set its status, and pin relevant intercepts from any monitored channel; each item retains its original metadata.

2

Enrich with context — add annotations, link policy violations, and pull in behavioral data: activity calendar, productivity stats, user relations graph, and Risk Analysis timeline. AI summaries are available with the Premium AI Server.

3

Export and close — export a structured evidence report via the Reports module; the Investigations Server tracks all cases and their history in the Administrator Console Status Monitor.

4

Trigger or search — start from a policy alert, a tip, or a proactive search using Information Search, Complex Search, or the User Activity profile.

1

Build the case — create a named case, set its status, and pin relevant intercepts from any monitored channel; each item retains its original metadata.

2

Enrich with context — add annotations, link policy violations, and pull in behavioral data: activity calendar, productivity stats, user relations graph, and Risk Analysis timeline. AI summaries are available with the Premium AI Server.

3

Export and close — export a structured evidence report via the Reports module; the Investigations Server tracks all cases and their history in the Administrator Console Status Monitor.

4

Arrow

Investigations by Plan

StandardCore employee activity monitoring.
Network traffic interception
USB control
Printers monitoring
Messengers interception
Browsers interception
and 4 more
Includes:
Anexet Activity
Most popular
AdvancedAdds DLP and deeper visibility.
Standard plan included
DLP features
Network shares monitoring
Keylogger
Webcam pictures
and 4 more
Includes:
Anexet DLP
Anexet Activity
All-in-one
PremiumAll-in-one solution.
Standard + Advanced plans included
Advanced search (digital fingerprints, hash search)
File systems monitoring
User relations analysis
Risk analysis
and 6 more
Includes:
Anexet DLP
Anexet Inventory
Anexet Activity
Anexet Ultimate

Frequently Asked Questions

Common questions about Anexet's Investigations module and how it handles incident evidence.

What is security incident investigation software?

Security incident investigation software lets an information security team collect, organize, and preserve digital evidence from monitored endpoints and communication channels to document a data-leak or insider-threat incident. Anexet's Investigations module does this within the same Client Console used for interception and policy management — no separate forensics tool required.

The Investigations module is included exclusively in the Premium plan. Standard and Advanced plans provide interception, search, and reporting but do not include the structured case-management workspace or the structured evidence export.

Yes. Anexet is deployed on-premise; the vendor has no access to your data. All intercepted evidence, case files, annotations, and exported reports remain on your organization's own servers throughout the investigation lifecycle.

No. Scinero Software Limited operates no cloud infrastructure that processes your data. The product runs inside your network perimeter, and the vendor has no technical pathway to intercepted content or case files.

Every channel Anexet monitors is available as an evidence source: email (SMTP, IMAP, MAPI, Exchange, M365), desktop and web messengers, file transfers (USB, cloud, FTP, network shares), file operations on workstations, screen recordings and screenshots, clipboard events, keylogger logs, webcam snapshots, and speech-to-text transcripts of voice communications — all on Premium.

Yes, on the Premium plan with the AI Server configured. The on-premise AI model generates summaries of intercepted email threads, messenger conversations, and documents, and can auto-assign status labels to incidents. This reduces manual reading time during complex multi-channel investigations. The AI model runs entirely on-premise — intercepted content is never sent to external services.

Yes. In the User Activity module, the analyst can open an employee's profile and launch the investigation wizard directly from that profile — without navigating away to start a new case manually.

Three professionals collaborating and looking at a tablet in a meeting

Build Your First Evidence Case

Tell us about your incident response workflow and what evidence sources matter most — we'll show you how the Investigations module fits and arrange a demo or a free trial of Anexet Ultimate.

I accept that my personal data can be processed in accordance with the Privacy Policy