Somewhere in your agency right now there is a case file with a screenshot in it. A threat sent over a messaging app. A profile page with a photograph and a name. A post that was up on Tuesday and gone by Thursday. Someone saw it, pressed two buttons, and the picture went into the file as the evidence.
It is the most common exhibit in our field now, and the least understood. A screenshot is a photograph of a screen. It records what the glass showed to one person at one moment. It does not record who wrote the words, when they were written, whether the page was live or a saved copy someone had edited, what sat one scroll below the visible edge, or whether the file in the case folder is the same file that was captured. Every one of those is a question a court can ask, and the picture cannot answer any of them.
The rule that governs the answer is short, the cases that apply it to social media are consistent, and the method that satisfies them is not hard. This issue is about all three.
What the rule asks
Federal Rule of Evidence 901(a) puts the whole requirement in one sentence: "the proponent must produce evidence sufficient to support a finding that the item is what the proponent claims it is." The rule then gives examples. The first is "Testimony that an item is what it is claimed to be," from a witness with knowledge. The fourth is "The appearance, contents, substance, internal patterns, or other distinctive characteristics of the item, taken together with all the circumstances." The ninth covers "Evidence describing a process or system and showing that it produces an accurate result."
Notice what the sentence does not say. It does not say the item must be proven genuine. It says the proponent must produce enough that a finder of fact could find it genuine. In Lorraine v. Markel, the 2007 opinion that became the roadmap for electronic evidence, the court described the evidence rules as "a series of hurdles to be cleared by the proponent of the evidence." Authentication is the second hurdle, right after relevance, and it is not a tall one. In United States v. Vayner the Second Circuit repeated a line from one of its own earlier decisions: "the bar for authentication of evidence is not particularly high."
The catch is the word "claims." A screenshot of a profile page, offered as a picture of a web page, is easy: the person who took it says that is what the screen showed. The same screenshot offered as the defendant's page, written by the defendant, is a different claim, and the picture alone does not carry it. Nearly every reported failure in this area is a proponent who proved the first claim and needed the second.
Three courts, one lesson
Maryland, 2011. In Griffin v. State the prosecution offered a printout of a MySpace profile it said belonged to the defendant's girlfriend. It carried a photograph, a date of birth, a location, and the line "snitches get stitches." The girlfriend had testified, but nobody asked her about the page. It came in through the lead investigator, who had printed it. The Court of Appeals of Maryland reversed and ordered a new trial. The photograph, "coupled with her birth date and location, were not sufficient 'distinctive characteristics' on a MySpace profile to authenticate its printout," because someone other than the girlfriend could have created the profile and written the post. Then the court did something useful. It listed three ways the State could have done it: ask the purported creator whether she made the profile and the post; examine the computer of the person who supposedly created it, its internet history and its hard drive, to see whether that machine originated the profile and the post; or obtain information from the social networking site itself linking the account to the person. The court called the list non-exclusive. Notice that the second method is a forensic examination.
Texas, 2012. In Tienda v. State the Court of Criminal Appeals went the other way on different facts. Printouts from three MySpace profiles came in at a murder trial, over a running objection, through the victim's sister. The pages carried photographs of the defendant, account names, comments and instant messages, and links to music, and the details in them fit the case. The court held that "the internal content of the MySpace postings . . . was sufficient circumstantial evidence to establish a prima facie case such that a reasonable juror could have found that they were created and maintained by the appellant." It also stated the judge's job in a sentence worth keeping: "The preliminary question for the trial court to decide is simply whether the proponent of the evidence has supplied facts that are sufficient to support a reasonable jury determination that the evidence he has proffered is authentic."
Federal, 2014. In United States v. Vayner the government offered a printout of a page from VK, a Russian social networking site, as the defendant's profile, to corroborate a cooperating witness about a screen name the defendant supposedly used. The witness who sponsored it was a federal agent who, on cross-examination, admitted a "cursory familiarity" with the site and did not know whether it verified anyone's identity before opening an account. The Second Circuit held that admitting the page was an abuse of discretion, that the error was not harmless, and vacated the conviction for a new trial. Its reasoning is the point of this issue: the fact that a page with the defendant's name and photograph existed on the internet "does not permit a reasonable conclusion that this page was created by the defendant or on his behalf." Everything on the page that pointed at the defendant was also known to the cooperating witness, and likely to others, some of whom might have had reasons to build a page in his name. The court declined to say what would have been enough.
Maryland, 2015. In Sublet v. State the same court that decided Griffin took three social media cases together and adopted the federal formulation: "in order to authenticate evidence derived from a social networking website, the trial judge must determine that there is proof from which a reasonable juror could find that the evidence is what the proponent claims it to be." In two of the three cases the evidence had come in, and the court upheld it. In the third the trial judge had kept it out, and the court upheld that too.
Four opinions across four years, and the lesson does not change. A name and a photograph on a page are not evidence of who made the page. The bar is low, but it is a bar, and the way over it is proof that ties the account to the person, not a better-looking screenshot.
What the picture cannot carry
Here is where the examiner's view of a screenshot differs from everyone else's. Look at what the file actually is.
It is an image, usually a PNG, made by the operating system at the moment someone pressed the buttons. On a current Android phone, the stock screenshot tool writes a little into the file: the date and time, the time zone offset, an identifier for the capture, and the version of the operating system. Other devices write less. None of them write the URL. None write the account that was logged in. None record what the page looked like a second earlier, or whether the content in the frame was rendered by the platform or typed into a saved copy of the page in a text editor. None produce a hash, so nothing in the file itself can later show that the copy in the case folder is the one that was captured. Everything a forensic acquisition records about a device, the picture does not have about a web page.
In nineteen years of forensic work I have watched the screenshot go from a curiosity to the first page in the file. The notes that should travel with it never caught up.
So a screenshot can say one thing well: this is what a screen showed to this person at this moment, if that person can testify to it. That is Rule 901(b)(1), and for a great deal of evidence it is enough. What it cannot say is who wrote the content, when, from where, or that the file is unaltered. Those have to come from somewhere else, and the time to collect them is while the page is still up.
How to capture so it survives
Make the witness before you make the picture. The person who saw the content is the authenticating witness under 901(b)(1). Write down, at the time: the URL, the date and time with the time zone, the device and browser, the account that was logged in, and what was clicked to reach the page. The screenshot illustrates that testimony. Without the notes, the witness is guessing on the stand about a picture that carries no date.
Capture more than the viewport. Take the full page, not the visible frame. Take the platform's own export or download where it offers one. Take the page source, or the content through the platform's interface. SWGDE's Best Practices for Acquiring Online Content (21-F-001, version 1.1) treats screenshots as one collection method among several, alongside browser utilities and platform APIs, and notes that a service API "can capture what is being seen on a webpage in plain view as well as critical metadata that are not available through web pages and screen captures."
Hash at capture, and write the hash down. The same SWGDE document: "NIST-approved secure hash algorithms should be used to calculate digests to validate and uniquely identify the entire collection data set, as well as the individual content (files) acquired, including graphical contents, underlying browser data, and documentary evidence." Record the tool and version that made the capture. This is what makes the file in the folder provably the file that was captured, and it is what the 2017 amendment to Rule 902 was written for. Rule 902(14) lets data copied from a device, storage medium or file be self-authenticated by a qualified person's certification that it was "authenticated by a process of digital identification." The Advisory Committee's note says what that means in practice: "Today, data copied from electronic devices, storage media, and electronic files are ordinarily authenticated by 'hash value'." No hash at capture, no certification later.
Freeze the platform's copy. For law enforcement, 18 U.S.C. § 2703(f) lets a governmental entity require a provider to "take all necessary steps to preserve records and other evidence in its possession pending the issuance of a court order or other process." The records "shall be retained for a period of 90 days, which shall be extended for an additional 90-day period upon a renewed request by the governmental entity." The letter takes ten minutes and costs nothing, and it turns a screenshot into the first page of a record the platform itself can later authenticate. Civil practitioners have the preservation letter and the subpoena. Either way, the platform's account records are Griffin's third method, and they are the piece that answers "who."
Tie the account to a person, on purpose. Griffin's second method is ours: the device, the browser history, the application data, the login tokens, the cached images, the drafts. If the account was operated from a phone you have lawful access to, the artifacts that show it are an examination away. If it was not, say so in the report, and let the attorney build the link from the platform records and the internal content, instead of leaving a jury to infer it from a photograph.
Describe the exhibit as what it is. "Screenshot of a web page, taken by the case detective on this date at this time from this account" is an honest exhibit description. "Defendant's Facebook post" is a claim. Write the first, and let the evidence for the second stand on its own.
The bar cuts both ways
Because the bar is low, careless captures get admitted all the time, and everyone in the room learns the wrong lesson. Then a case arrives where the content matters, defense counsel has read Griffin and Vayner, and the kind of picture that carried a hundred plea negotiations stops at the door. Two convictions in the cases above were set aside for new trials over exactly that.
For examiners on the defense side, the same list is your cross-examination outline. Who captured this. When. From what account. Where are the notes. Where is the hash. Was a preservation request sent. What ties this account to my client other than a name and a face that everyone in this courtroom also knows.
The screenshot shows what was on the screen. Everything else, you have to bring.
Take it further
A housekeeping note with a date on it, and then I will let it go. Tomorrow night, Wednesday, September 30, at 11:59 pm Central, the $497 tuition on the two fundamentals courses ends. From October 1, Computer Forensics Fundamentals and Mobile Device Forensics Fundamentals are $697 each. Nothing else moves: Drone Forensics for Law Enforcement stays $997, the Certified OSINT Investigator, Court-Ready Practitioner program stays $2,497, and All-Access stays $2,997. If a purchase order will not clear by tomorrow, a written agency quote issued before the change holds its price for 90 days. Email info@thewaldrepcompany.com and I will send one, with a W-9 or a sole-source letter if your file needs them.
Course pages: Computer Forensics Fundamentals · Mobile Device Forensics Fundamentals
All-Access is all four online courses in one enrollment: four separately verifiable certificates, 86 CPE hours, every template library we teach from, and twelve months of access per course. All four are listed in the CISA National Initiative for Cybersecurity Careers and Studies (NICCS) Education and Training Catalog; a listing is not an endorsement, but it is often what a training officer needs to see. Purchased separately, the four courses total $4,488 today and $4,888 from October 1. All-Access is $2,997 either way, so the arithmetic gets better after the change, not worse. Government purchase orders, net-30 invoicing, and agency licensing are available, and if you already bought one of the four, your tuition credits in full toward the bundle for 90 days: email info@thewaldrepcompany.com from your enrollment address and we will send an upgrade link for the difference.
If this issue was useful, subscribe to Digital Forensics Today below and send it to the detective whose case file has a screenshot in it, or to the attorney who is about to offer one. Every issue is about doing OSINT and digital forensics that stands up when someone asks how you know.
Sources and further reading
- Fed. R. Evid. 901. www.law.cornell.edu/rules/fre/rule_901
- Fed. R. Evid. 902(13) and (14), added by the amendment effective December 1, 2017, with the Committee Notes. www.law.cornell.edu/rules/fre/rule_902 and the official text at www.uscourts.gov/sites/default/files/document/federal-rules-of-evidence.pdf
- Lorraine v. Markel American Insurance Co., 241 F.R.D. 534 (D. Md. 2007). www.govinfo.gov/content/pkg/USCOURTS-mdd-1_06-cv-01893/pdf/USCOURTS-mdd-1_06-cv-01893-0.pdf
- Griffin v. State, 419 Md. 343, 19 A.3d 415 (2011). www.mdcourts.gov/data/opinions/coa/2011/74a10.pdf
- Tienda v. State, 358 S.W.3d 633 (Tex. Crim. App. 2012). www.courtlistener.com/opinion/2947098/tienda-ronnie-jr/
- United States v. Vayner, 769 F.3d 125 (2d Cir. 2014). nys-fjc.ca2.uscourts.gov/programs/10-23-19%20-%20US%20v.%20Vaynor%20789%20F.3d%20125%20(2014).PDF
- Sublet v. State, 442 Md. 632, 113 A.3d 695 (2015). www.mdcourts.gov/data/opinions/coa/2015/42a14.pdf
- 18 U.S.C. § 2703(f). www.law.cornell.edu/uscode/text/18/2703
- Scientific Working Group on Digital Evidence, Best Practices for Acquiring Online Content, 21-F-001, version 1.1 (2024). www.swgde.org/wp-content/uploads/2024/04/2024-03-15-SWGDE-Best-Practices-for-Acquiring-Online-Content-21-F-001-1.1.pdf
- Android Open Source Project, SystemUI screenshot exporter (the fields the stock Android screenshot tool writes into the image). android.googlesource.com/platform/frameworks/base/+/refs/heads/main/packages/SystemUI/src/com/android/systemui/screenshot/ImageExporter.java
- Earlier issues referenced: Verified Is Not Complete (hashing). thewaldrepcompany.com/newsletter/verified-is-not-complete/