Evidence Types
Create and manage Evidence Types used to categorize devices, accounts, data sources, and other Evidence Items throughout Monolith.
Evidence Types provide a consistent way to categorize the different kinds of Evidence Items your organization handles in Monolith.
An Evidence Item may represent a physical device, cloud account, email account, storage media, or another source of data. Evidence Types help organize those records into meaningful categories.
Consistent Evidence Types make it easier to filter, report on, and understand the volume and makeup of Evidence across your organization.
View Evidence Types
The Evidence Types settings page displays the Evidence Types currently configured for your organization.
Each Evidence Type also shows the number of Evidence Items currently associated with it.
Use this list to review the categories available when creating or updating Evidence Items.

Create an Evidence Type
To create a new Evidence Type:
Select Create Evidence Type.
Enter the name of the new Evidence Type.
Select Create Evidence Type to save it.
The new type becomes available when creating or updating Evidence Items throughout Monolith.
Choose names that are clear, recognizable, and meaningful to the people entering and reviewing Evidence.

Choosing Evidence Types
Evidence Types should reflect the kinds of sources your organization commonly receives or examines.
Examples might include:
Smartphone
Tablet
Desktop
Laptop
Hard Drive
Removable Media
Email Account
Cloud Account
Virtual Machine
Network or Cloud Service
Other organization-specific Evidence categories
The appropriate list will vary by organization.
A law enforcement lab may focus heavily on physical devices, while a corporate, legal, or incident response team may also work with email accounts, cloud environments, SaaS platforms, or other non-physical sources.
Evidence Types and Reporting
Evidence Type is an important reporting and filtering field.
For example, consistent Evidence Types can help answer questions such as:
How many mobile devices did we receive this year?
How many email or cloud accounts are currently being worked?
What types of Evidence make up most of our workload?
Which Evidence Types are associated with the largest amount of recorded data?
Keeping Evidence Types clean and consistent makes organization-wide Evidence views and reporting more useful.
See Evidence Items for more information about the global Evidence table and Evidence metadata.
Delete an Evidence Type
Evidence Types can be deleted when they are no longer needed.

If Evidence Items are currently associated with the Evidence Type being deleted, those items must be reassigned to another existing Evidence Type before deletion can be completed.
Review the Evidence Items associated with an Evidence Type before deleting it. Existing Evidence Items must be reassigned so their categorization is preserved.
Recommended Practices
Create Evidence Types that represent meaningful categories of devices, accounts, or data sources.
Keep naming consistent across the organization.
Avoid duplicate or nearly identical types.
Use broad enough categories to support useful long-term reporting.
Add new Evidence Types when your organization begins handling a genuinely different class of Evidence.
Review unused or outdated Evidence Types periodically.
Consider how Evidence Types will appear in filters, exports, dashboards, and reports.
Related Documentation
Last updated
Was this helpful?