Network-based digital evidence is digital evidence produced as a result of communications over a network. It is a subset of Digital Evidence, but it is distinguished by its extreme volatility and the difficulty of preserving or authenticating it.

Unlike data stored on hard drives or RAM, network-based evidence is often transient:
- Packets travel across the wire in milliseconds.
- Switch caches and router tables clear quickly.
- Web content can vary depending on location and time.

This volatility makes collection urgent. Investigators often rely on packet captures, flow records, IDS/IPS logs, and other network monitoring techniques. Because the source that generated the evidence may not be identifiable or obtainable, authenticity and chain of custody can be harder to establish than with static media.

The requirements for admissibility of network-based digital evidence are described as "murky" in the text. The investigator must still demonstrate that the evidence is relevant and authentic, even when the original source cannot be produced.

Source: Network Forensics: Tracking Hackers through Cyberspace, §1.3.8.