This guide provides IT Administrators and Systems Engineers with the technical specifications required to securely deploy the Exhibit In-Sight Desktop/MDT application and the Android Mobile companion app across your agency's endpoints. Please review the network, system, and group policy requirements to ensure successful deployment alongside existing Endpoint Detection and Response (EDR), Mobile VPN, and firewall infrastructure.
.eis_mobile archive creation.KeyguardManager.The software suite utilizes an air-gapped wireless architecture. The desktop application acts as a localized HTTPS server communicating with mobile devices via a WPA2-secured Wi-Fi hotspot or local cruiser subnet.
51038 (HTTPS / TLS 1.3): Primary endpoint for encrypted data synchronization (JSON payloads, Multipart image transfers, and audit log ingestion). An ephemeral 2048-bit RSA X.509 certificate is dynamically generated in memory on startup. Mobile clients enforce strict certificate pinning against the exact SHA-256 fingerprint displayed in the pairing QR code.51039 (Local Discovery Beacon Only — Zero Evidence): Used strictly for unencrypted, localized subnet discovery broadcasts. Mobile clients broadcast DISCOVER_MDT_REQUEST across the local subnet, and MDTs respond with DISCOVER_MDT_RESPONSE containing only the workstation computer name, active TCP port, session license GUID, and the public TLS certificate SHA-256 fingerprint. Zero evidentiary data, case notes, suspect information, occurrence numbers, or photographs are ever transmitted over UDP. 100% of case and evidence data is strictly restricted to encrypted TLS 1.3 communications over TCP Port 51038. (Note: Enterprise Wi-Fi controllers configured to drop 255.255.255.255 subnet broadcasts will suppress UDP auto-discovery; in such environments, scanning the on-screen QR code connects devices directly via TCP Port 51038).Many agencies deploy persistent Mobile VPN clients (e.g., NetMotion Mobility, Absolute Secure Access) on in-vehicle MDTs. To ensure uninterrupted mobile device pairing:
192.168.137.0/24) and local cruiser Wi-Fi subnets. If the Mobile VPN client forces all local adapter traffic through a centralized gateway, mobile devices will be blocked from reaching the MDT on TCP Port 51038.COMPUTERNAME environment variable, ensuring that virtual adapter addresses created by Mobile VPNs do not alter or obscure the physical workstation audit record.At application startup, the MDT queries the local time provider (w32tm /query /source) and logs the active clock source into the audit trail. If the machine cannot resolve a network time source, it logs CMOS Local Hardware Clock.
W32Time) is set to Automatic startup on all MDT endpoint images and configured to synchronize with your agency's Active Directory Domain Controller or an authorized stratum-1 NTP source via cellular modem.The desktop software requires periodic outbound HTTPS (TCP 443) access to communicate with our licensing verification server. This is a lightweight HTTP GET request containing your agency's unique billing key.
https://api.exhibitinsight.com/verify-license (Hosted in Google Cloud — Toronto, Canada region northamerica-northeast2).The MDT application utilizes high-performance, non-blocking Java NIO FileChannel streams with active OS-level file locking (.lock files) to prevent multi-process data corruption during rapid live evidence logging. To avoid false-positive quarantines, performance degradation, or deadlocks caused by aggressive Endpoint Detection and Response (EDR) platforms (e.g., CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne), please configure the following behavioral and directory exclusions:
Exhibit In-Sight.exe and underlying runtime binary javaw.exe within the installation directory).-ExecutionPolicy Bypass flag) to interact with the Windows.Networking.NetworkOperators.NetworkOperatorTetheringManager API to programmatically activate and configure the mobile hotspot. EDR rules must allow this specific tethering script execution.HKEY_CURRENT_USER\Software\JavaSoft\Prefs\com\exhibitinsight\collection. This path stores agency billing keys, department defaults, salted officer PIN hashes, and dynamic machine salts.*.eis.lock or temporary atomic files (*.tmp) in directories where officers save active case containers.eis_active_workspace_* and eis_conflict_check_* within %TMP% (or %USERPROFILE%\AppData\Local\Temp), and allow text log writes to %LOCALAPPDATA%\ExhibitInSight\logs (or %USERPROFILE%\.eis\logs). Automatic pruning removes diagnostic logs older than 14 days.Exhibit In-Sight Backups) adjacent to the active case file and applies the OS-level dos:hidden attribute (retaining up to 3 generational backups). EDR policies must allow the application to create, modify, and restore these files without flagging them as anomalous behavior.System.getProperty("user.name")). Officers register their Name and Badge ID and set a 4-digit numeric Quick PIN (stored locally as a salted SHA-256 hash) for auditable, sub-second user switching on shared MDTs.SESSION_LOCKED_INACTIVITY entry to the immutable audit ledger. The active officer must input their registered 4-digit PIN to resume operations, which logs a corresponding SESSION_UNLOCKED audit event.The Android companion application is distributed as a signed .apk download, suitable for deployment via your agency's Mobile Device Management (MDM) solution (e.g., Microsoft Intune, VMware Workspace ONE, SOTI MobiControl).
KeyguardManager. Devices lacking an active PIN, Pattern, or Biometric lock are blocked from opening the evidence container and directed to Android Security Settings.allowBackup="false". This prevents the Android OS from backing up the app's secure internal sandbox to personal cloud accounts (Google Drive, Samsung Cloud).NEARBY_WIFI_DEVICES; on legacy versions, the Android OS mandates ACCESS_FINE_LOCATION to allow an application to discover and connect to local Wi-Fi direct network SSIDs. The application contains zero GPS tracking libraries and does not record, track, or transmit geographic coordinates. This permission is utilized strictly for local MDT Wi-Fi hotspot connectivity.CAMERA permission is required to photograph exhibits and scan the MDT pairing QR code; VIBRATE provides haptic feedback upon successful scan acquisition.All case files generated by the MDT application are compiled as proprietary .eis container files (structured, uncompressed ZIP archives containing data.json, raw JPEGs, and warrant scans). In field-offline environments, mobile devices can also export self-contained .eis_mobile archive packages for manual USB or email transfer to the MDT.
.eis containers and mobile SQLite databases do not apply proprietary file-level encryption. Data protection at rest relies entirely on host operating-system encryption:
.eis container files must reside on local, non-synchronizing disk storage (e.g., C:\Cases\). Hosting active working directories inside real-time cloud-sync folders (Microsoft OneDrive, SharePoint, Google Drive, Dropbox) causes operating-system file-locking collisions with Java NIO FileChannel streams, resulting in save thread deadlocks and container corruption.