> ## Documentation Index
> Fetch the complete documentation index at: https://syteca.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Forensic Export

> Syteca Forensic Export: produce evidence-grade exports of recorded sessions, with SHA256 integrity verification, password protection, and a standalone Forensic Player for third-party playback.

## Hand the evidence to your legal team without handing them your monitoring console

Recording every session sounds powerful in a sales meeting. The moment you actually need to use the recording - to defend a wrongful termination, support a fraud investigation, respond to an e-discovery request, or hand evidence to law enforcement - the question becomes harder: how do you give a recorded session to someone who doesn't have access to your monitoring platform, in a form their lawyer will accept as evidence?

Many platforms answer this with "export a video file" or "download a screen recording." Those work, until opposing counsel asks how you can prove the video wasn't edited. SHA256 hash? Where? Password protection? None. Standalone player your forensic team can use without a Management Tool license? You're emailing them an MP4 and hoping they have VLC.

**Syteca Forensic Export** is built for the moment a recording leaves the platform and becomes evidence. Sessions export as encrypted `.efe` files with a **SHA256 hash** for integrity verification, optional **password protection**, optional restriction to a specific time window inside a session, and playback in the **Syteca Forensic Player** - a standalone Windows/macOS/Linux application that opens `.efe` files without needing Management Tool access. The Forensic Export History tab is the audit trail of every export performed, by whom, with what comment, and with what hash.

<Info>
  **Use Forensic Export when you need to:**

  * Produce **legal-grade evidence** for litigation, e-discovery requests, or law enforcement, with SHA256-verifiable integrity.
  * Support **HR investigations and wrongful-termination defense** with session recordings the HR team can review independently.
  * Comply with **SOC 2 incident response evidence requirements**, **ISO 27001 incident records**, **GDPR data subject access requests**, or **PCI DSS forensic investigation needs**.
  * Share specific session evidence with **third-party investigators, auditors, or insurance carriers** without granting them access to your monitoring platform.
  * Maintain a **chain-of-custody audit trail** for every recording that leaves the platform - who exported it, when, what comment they attached, what hash it produced.

  **Pair it with the [Audit Log](/docs/administration/audit-log)** - Forensic Export answers "what did the user do?"; the Audit Log answers "who in *our* organization handled this recording, and when?"
</Info>

<Note>
  Forensic Export requires the [**Viewing Monitoring Results permission for Clients**](/docs/administration/users/client-permissions) - you can only export sessions from Clients you have permission to view.
</Note>

## How Forensic Export works

Every Forensic Export produces an encrypted file that can be played back outside the Management Tool. Two file formats depending on the recording mode:

| Mode                                                                                                                        | Export format                            | Contents                                                                                               |
| --------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------ |
| **Interval Capture** *(screen captures)*                                                                                    | `.efe` *(Syteca Forensic Player format)* | Screen captures **plus** metadata (keystrokes, clipboard, URLs, alerts), optionally password-protected |
| **[Full Motion Capture](/docs/session-monitoring/recording/user-activity-recording#activity-recording-configuration)** *(video)* | `.mp4`                                   | Video only, no metadata, no password protection                                                        |

In both cases, the export file lives on the Application Server in the **Forensic Export History** tab - downloadable, hashed, and audited.

Two entry points for triggering an export:

| Entry point                                | Best for                                                                                  |
| ------------------------------------------ | ----------------------------------------------------------------------------------------- |
| **From the Session Player** *(Tools menu)* | Exporting **one** session, with the option to export only a specific time-window fragment |
| **From the Sessions List** *(Bulk Action)* | Exporting **one or many** sessions in a single operation                                  |

## Export a single session (or a session fragment)

<Frame caption="The Session Forensic Export dialog - fragment-or-full export, optional text data, optional password protection, and an audit-trail Comment.">
  <img src="https://mintcdn.com/syteca/FKrkO8bEqEQ6WSgs/images/session-monitoring/forensic-export-dialog.png?fit=max&auto=format&n=FKrkO8bEqEQ6WSgs&q=85&s=abccac857ffa6529b500772d42007582" alt="Session Forensic Export pop-up showing fragment vs full session radio buttons, From/To pickers, Include text data and password checkboxes, Comment field" width="1902" height="895" data-path="images/session-monitoring/forensic-export-dialog.png" />
</Frame>

Use this entry point when you're already watching a session in the Session Viewer and want to export the whole session - or a specific minute-by-minute slice of it.

<Steps>
  <Step title="Open the session">
    Sign in to the Management Tool, open the session in the [Session Viewer](/docs/session-monitoring/player/overview).
  </Step>

  <Step title="Open the Forensic Export dialog">
    In the **Session Player** pane, click the **Tools** icon in the top right, then select **Forensic Export** in the drop-down list.
  </Step>

  <Step title="Choose what to export">
    In the **Session Forensic Export** pop-up, select one:

    * **Export session fragment starting from current Player position** - enter the **From** and **To** dates and times for the slice to export.
    * **Export full session** - export the whole session.
  </Step>

  <Step title="Choose options">
    Optionally configure:

    | Option                    | Effect                                                                                                                                                                               |
    | ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
    | **Include text data**     | Includes keystrokes and clipboard text in the export. Without this, only screen captures and basic metadata are included.                                                            |
    | **Protect with password** | Encrypts the exported file. The recipient needs this password to open it in the Syteca Forensic Player. Enter the password in both the **Password** and **Confirm password** fields. |
    | **Comment**               | Free-text comment displayed in the **Comment** column on the Forensic Export History tab - useful for "Ticket #4523, requested by Legal" attribution.                                |

    <Warning>
      In [Full Motion Capture](/docs/session-monitoring/recording/user-activity-recording#activity-recording-configuration) mode, the **Include text data**, **Protect with password**, **Password**, and **Confirm password** options aren't available - video-mode exports are MP4 only.
    </Warning>
  </Step>

  <Step title="Export and download">
    Click **Export**. The **Forensic Export History** tab opens, showing the export progress. When status changes to **Generated**, click the **Download** icon to download the file.
  </Step>
</Steps>

## Export multiple sessions in bulk

Use this entry point when you need to export many sessions at once - for example, all sessions from a specific user across a specific time window for an investigation.

<Steps>
  <Step title="Open the Sessions List">
    Sign in to the Management Tool, click **Activity Monitoring** in the left navigation.
  </Step>

  <Step title="Filter to the sessions you need">
    On the **Client Sessions** tab, [filter the list](/docs/session-monitoring/sessions-list#filter-sessions) to narrow it to the sessions you want to export.
  </Step>

  <Step title="Select sessions">
    Select the checkboxes next to the required sessions, or the **Select All** checkbox in the column header to select all visible sessions.
  </Step>

  <Step title="Start the export">
    Click **Bulk Action** in the top left, then select **Forensic Export** in the drop-down.

    <Warning>
      Forensic export of many sessions can take considerable time and **may impact Application Server performance** while running. Avoid bulk-exporting hundreds of sessions during business hours.
    </Warning>
  </Step>

  <Step title="Choose options">
    In the **Sessions Forensic Export** pop-up:

    * Optionally select **Protect with password** and enter a password in both fields.
    * Optionally enter a **Comment** that will appear in the Forensic Export History.

    Click **Export**.
  </Step>

  <Step title="Download from the history">
    The **Forensic Export History** tab opens. As each session finishes, its **Download** icon becomes active - download the file once status is **Generated**.
  </Step>
</Steps>

<Note>
  Multi-session bulk exports don't support the **Include text data** option - bulk exports always include text data (keystrokes and clipboard) where the exporting user has the [Viewing Text Data permission](/docs/administration/users/client-permissions) for the Client.
</Note>

## The Forensic Export History tab

<Frame caption="The Forensic Export History tab - every export ever performed, with SHA256 hashes for chain-of-custody verification and a download link for the standalone Syteca Forensic Player.">
  <img src="https://mintcdn.com/syteca/FKrkO8bEqEQ6WSgs/images/session-monitoring/forensic-export-history.png?fit=max&auto=format&n=FKrkO8bEqEQ6WSgs&q=85&s=f0ee146c8a0ef6c929d329d0e7c64501" alt="Forensic Export History tab showing multiple exports with Export Type, Status, File Size, SHA256 hashes, and Comment columns plus the Syteca Forensic Player download link" width="1896" height="646" data-path="images/session-monitoring/forensic-export-history.png" />
</Frame>

Every export ever performed is recorded on the **Forensic Export History** tab on the Activity Monitoring page - yours and other users'. This is both the download surface and the chain-of-custody audit trail.

The **Syteca Forensic Player** download link sits at the top of the tab - click it to download the standalone player you'll need to play the `.efe` files. See [Play an exported session](#play-an-exported-session) below.

### The grid

| Column                                        | Shows                                                                                                |
| --------------------------------------------- | ---------------------------------------------------------------------------------------------------- |
| **Export Date**                               | When the export was performed.                                                                       |
| **Client Name**                               | The Client computer the session came from.                                                           |
| **User**                                      | The endpoint user the session belongs to.                                                            |
| **Session Start Date** / **Session End Date** | When the session covered by this export started and finished.                                        |
| **Export Type**                               | The export scope (see [Export types](#export-types) below).                                          |
| **Status**                                    | Export progress - **In progress** *(with %)*, **Generated**, **Generation failed**, or **Canceled**. |
| **File Size**                                 | Resulting file size, or **n/a** for failed exports.                                                  |
| **File Hash (SHA256)**                        | SHA256 hash for [integrity verification](#verify-the-integrity-of-an-exported-session).              |
| **Comment**                                   | The comment entered when the export was started.                                                     |
| **Download** *(icon)*                         | Click to download the exported file.                                                                 |
| **Remove All** *(in header)*                  | Delete every export from the Application Server.                                                     |
| **Remove** *(icon)*                           | Delete an individual export.                                                                         |

### Export types

| Type                            | Meaning                                                                                                           |
| ------------------------------- | ----------------------------------------------------------------------------------------------------------------- |
| **Full Session**                | The whole session, including text data (keystrokes and clipboard)                                                 |
| **Full Session (no text data)** | The whole session, screen captures and basic metadata only - no keystrokes or clipboard                           |
| **Truncated Full Session**      | The session had **more than 20,000 activities**; the export was truncated to **1 GB** to keep the file manageable |
| **\[From] - \[To]**             | A session fragment, restricted to the time window specified at export time                                        |

<Note>
  Forensic Export tasks still in progress can be canceled on the [Tasks List](/docs/administration/dashboards/system-health-dashboards#tasks-list) tab of the System Health page.
</Note>

## Play an exported session

Exported `.efe` files play in the **Syteca Forensic Player** - a standalone application that doesn't require Management Tool access. Useful for forensic investigators, third-party auditors, legal teams, and anyone else outside the Syteca user base who needs to review session evidence.

<Steps>
  <Step title="Download the Forensic Player">
    On the **Forensic Export History** tab in the Management Tool, click the **Syteca Forensic Player** link at the top of the page to download the installer.
  </Step>

  <Step title="Install (per OS)">
    Install on the computer where the recipient will review the evidence:

    <Tabs>
      <Tab title="Windows">
        Run the Syteca Forensic Player installer. The application installs as a normal Windows application - no additional dependencies.
      </Tab>

      <Tab title="macOS / Linux">
        The Forensic Player requires **Mono Framework** on macOS and Linux. Install Mono first by following the instructions at [mono-project.com/docs](http://www.mono-project.com/docs/), then install the Forensic Player.
      </Tab>
    </Tabs>
  </Step>

  <Step title="Open the .efe file">
    Launch the Syteca Forensic Player and open the `.efe` file. If the file is password-protected, enter the password when prompted.

    <Note>
      For MP4 exports from Full Motion Capture mode, any standard video player can be used - no Syteca Forensic Player needed.
    </Note>
  </Step>
</Steps>

### What you see in the Syteca Forensic Player

The Forensic Player mirrors the layout of the in-product [Session Viewer](/docs/session-monitoring/player/overview):

| Pane                                    | Contains                                                                                                                                                                                                         |
| --------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Session Player**                      | Screen captures of the recorded session, or - for Linux Clients with X Window System enabled - the GUI captures, or - for SSH/terminal sessions - a graphical representation of the terminal as the user saw it. |
| **Metadata grid**                       | Activity Time, Activity Title, Application Name, URL, Text Data, Alert/USB Rule columns *(Windows/macOS)* - or Activity Time, Command, Function/Action, Parameters, Alert *(Linux)*.                             |
| **Details area** *(Windows/macOS only)* | Keystrokes and clipboard text for the selected event, alert/USB device information, and URLs visited.                                                                                                            |

<Note>
  If the user performing the export doesn't have the [Viewing Text Data permission](/docs/administration/users/client-permissions) for the Client, the exported file won't contain any text data - the Details area will be empty in the Forensic Player.
</Note>

<Note>
  If **Enable screen capture recording along with user activity recording** wasn't selected on the Client, the exported sessions won't contain any screen captures - only metadata.
</Note>

### Forensic Player controls

| Action                                        | Control                                                         |
| --------------------------------------------- | --------------------------------------------------------------- |
| **Play / Pause**                              | Play/Pause button, or **Space** in Full Screen mode             |
| **Previous / Next record**                    | Navigation control buttons                                      |
| **Zoom into a specific area**                 | Magnifying Glass icon                                           |
| **Full Screen**                               | Double-click the screen captures, or click the Full Screen icon |
| **Playback speed**                            | Speed icon - 1, 2, 4, 8, or 16 frames per second                |
| **Switch monitor** *(multi-monitor sessions)* | Monitor icons (1, 2, etc.) or show-all-screens icon             |

## Verify the integrity of an exported session

The whole point of a SHA256 hash on the Forensic Export History tab is to **prove the file you're handing over is byte-identical** to what came out of Syteca. Any opposing counsel, auditor, or forensic investigator can independently verify the file by recomputing the SHA256 on their copy and comparing it to what's on the Forensic Export History tab.

<Steps>
  <Step title="Get the hash from Syteca">
    On the **Forensic Export History** tab, copy the value from the **File Hash (SHA256)** column for the exported session.
  </Step>

  <Step title="Compute SHA256 on the file">
    On the computer that has the exported file, compute its SHA256 hash:

    <Tabs>
      <Tab title="Windows (PowerShell)">
        ```powershell theme={"system"}
        Get-FileHash -Algorithm SHA256 -Path "C:\path\to\session.efe"
        ```
      </Tab>

      <Tab title="macOS">
        ```bash theme={"system"}
        shasum -a 256 /path/to/session.efe
        ```
      </Tab>

      <Tab title="Linux">
        ```bash theme={"system"}
        sha256sum /path/to/session.efe
        ```
      </Tab>
    </Tabs>
  </Step>

  <Step title="Compare">
    Compare the two hashes. They must match exactly, character-for-character. If they don't, the file has been modified or corrupted between Syteca and the comparison point.
  </Step>
</Steps>

<Tip>
  For high-stakes evidence handovers, capture the SHA256 hash on a separate channel - for example, the original SHA256 in a signed PDF or email, the file itself by a different transport. If both arrive together over the same channel, an attacker who tampered with one can also tamper with the other.
</Tip>

## Related

<CardGroup cols={2}>
  <Card title="The Sessions List" icon="list" href="/docs/session-monitoring/sessions-list">
    Where bulk Forensic Export starts - find and filter the sessions to export.
  </Card>

  <Card title="Session Viewer" icon="play-circle" href="/docs/session-monitoring/player/overview">
    Where single-session Forensic Export starts (via the Tools menu).
  </Card>

  <Card title="Audit log" icon="scroll-text" href="/docs/administration/audit-log">
    The audit trail of every administrator action - including who exported what.
  </Card>

  <Card title="Full Motion Capture" icon="video" href="/docs/session-monitoring/recording/user-activity-recording#activity-recording-configuration">
    The recording mode that produces MP4 exports instead of EFE.
  </Card>
</CardGroup>
