Skip to content
FRP-139 Fraud & Financial Crime

What should be preserved about connected devices?

Connected-device information can help identify which systems were using a network at a particular time, but it must be preserved with context.

Avoid this assumption: A device name or IP address identifies the person using it. Names can be generic, user-defined or reused, and addresses may change.

Record the router, network, account, page, date, time and time zone.

Capture each visible device name, hostname, MAC address, assigned IP address, connection type and interface.

Preserve first-seen, last-seen, lease start, lease expiry and activity status where available.

Record whether the device is wired, wireless, guest, blocked, trusted, managed or currently offline.

Capture manufacturer information, signal strength, access point and network name where shown.

Do not rename, block, disconnect or select a device merely to investigate it.

If the list changes, record the earlier and later states separately.

Be aware that privacy features can randomise wireless MAC addresses, and one device may appear under several identifiers.

Likewise, one identifier may represent a virtual machine, extender, shared system or network intermediary rather than an individual endpoint.

Where attribution matters, compare the network record with device evidence, provider records and other investigative material.

Record any limit on the visible history or number of devices shown.

Record whether the list is current, historic, cached or limited to one access point. Preserve any grouping by household, site, VLAN, guest network or managed profile.

Operational takeaway

Preserve connected-device identifiers, timing and connection context exactly as shown, while keeping technical network presence separate from personal attribution.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.