Skip to content
All Docs

Report, Evidence Citation, and Integrity Guide

Report, Evidence Citation, and Integrity Guide#

unJaena AI reports are investigation aids for fast sharing and review. Legal, disciplinary, or court-facing decisions should still be based on independently verified original evidence, acquisition authority, and chain-of-custody records.

Report Structure#

SectionDescription
SummaryKey findings, risk level, and investigation scope
Key FindingsEvidence-backed conclusions and confidence labels
TimelineImportant events ordered by time
Evidence CitationsArtifact references behind each claim
MITRE MappingTactics and techniques related to incident or malware activity
Next ActionsAdditional collection, account action, blocking, or verification steps

Checking Evidence Citations#

  1. Open the cited artifact.
  2. Confirm time, user, filename, path, hash, and raw log context.
  3. Check whether another artifact supports the same event.
  4. Mark direct evidence and circumstantial context separately.

Integrity Workflow#

ItemPurpose
SHA-256 hashDetect content changes
Original path and metadataPreserve source context
TimestampsSeparate created, modified, accessed, and collected times
Audit logsRecord upload, analysis, deletion, and sharing actions
Retention policyConfirm deletion schedule and legal hold status

Report Writing Cautions#

  • Do not rely on the AI conclusion alone.
  • Avoid using uncited statements as core findings.
  • Distinguish timezone, system clock skew, backup creation time, and user activity time.
  • Label inference as possible, likely, or requiring further confirmation.
  • Verify original evidence and acquisition process before legal use.

Next Steps#

Continue in the service

Move from this guide into a sample workflow or the relevant upload surface. Upload real evidence only when you have lawful authority.