# The role of the user interface in digital investigations: how UI convenience and intuitiveness speed up data analysis and search Nikita Pavlov · Zero eDiscovery MOSCOW FORENSICS DAY ’25 · Day 2 — Friday, 12 September 2025: information security day · Scheduled 15:35–16:05 · In the recording 07:28:23–07:51:30 Talk transcript · https://2025.moscow-forensics-day.workers.dev/en/transcript/17-pavlov Summary: https://2025.moscow-forensics-day.workers.dev/en/summary/17-pavlov · Slides: https://2025.moscow-forensics-day.workers.dev/en/slides/16-pavlov-interfeis-rassledovaniya · Watch from 07:28:23: https://youtu.be/4V7Wez3L_58?t=26903 --- ## Moderator's introduction Testing, testing, testing. So, friends, as I already said, let's open the third and final block of our two-day conference. What is the role of the user interface in a digital investigation? And how does all that convenience help us cope with it? Nikita Pavlov from Zero eDiscovery will tell us about that. Let's give him a round of applause. Next slide. The clicker. Flip it over here. And the microphone. ## Talk and Q&A Good afternoon, dear participants. Last year, those who were here probably remember, we talked about a methodology for conducting investigations using forensic data analysis systems. This year we decided to diversify our talks a bit, I suppose, to diversify what we narrate, what we talk about. And UI turned out to be the topic that's probably covered the least, in the work of law enforcement agencies, in the work of people who do forensics, computer forensics, various private cases. Accordingly, as co-founder and co-creator of the Zero eDiscovery platform, designed for conducting various investigations and audits, and the actual designer of its user interface and user experience, I'd like to share some practical examples, practical tips on how you can improve your interaction, first of all, with the developers of the products you use, and secondly, I suppose, highlight some interesting features that you may not have noticed before. The first thing I want to say, to raise as a problem, is one that is present in most interfaces, basically, that are developed by people who aren't specialists, not by people who are actually trained, who went through a certain school of training in design, in engineering. The word "design" in itself gets lost, and it's usually understood as a way to make something beautiful and attractive, but at the same time, I think the word "design" should be understood the way it's understood in English and used very often to mean engineering rather than decoration or anything else. So the first thing I want to say is information overload. In almost every interface I personally encountered during my work, which I at some point rewrote or whatever else, very often everything is piled into one heap. And you've surely come across situations where you're in an interface and just don't always understand how to accomplish a particular task that you're facing. Accordingly, there's an interesting phrase here, Hick's law: the more choices, the longer the decision. Absolutely obvious: the more buttons in an interface, the harder it is to work in it, because you have to hunt for them. Not if, but surely everyone uses Microsoft products: Word, Excel. Some have probably switched now to Yandex or VK products. And everyone knows perfectly well that in those interfaces you use at most 6 or 7 functions. Accordingly, my goal at Zero eDiscovery, in development generally, is to provide the clearest possible interface, as simple, intuitive and accessible as possible for accomplishing the primary task, rather than learning a new software product. Again, I'll repeat what I said at the start and expand on it a bit: user interface and user experience are not about beauty. Although there's something to the aesthetic side, but, as perhaps many will confirm, many have come across this: in the world of, say, the military industry, everything is very beautiful, certain objects, for example tanks, maybe combat vehicles, aircraft and so on. And that beauty we see is directly tied to the fact that, first of all, nothing's superfluous, because everyone knows perfectly well that the more loaded up a certain machine, a certain device is, the harder it is to control, and accordingly the harder it is to operate. So the first term we want to remember today is what user experience actually is in the first place. User experience is also comparable to the word ergonomics, which you've come across and may have used for objects of the physical world. Ergonomics in itself is a property of an object, first of all the fit of its external parameters to its purpose, that is, a hammer, say, that's comfortable to hold, a screwdriver that is comfortable to hold, an ergonomic handle is used. The same can be said about a tactical grip. That is, all of this is first of all not about aesthetics, but specifically about utility. Accordingly, user experience is, first of all, easiest to understand as the utility of the software product itself. User interface, in turn, is its software implementation, its implementation in the interface, that can be considered the part that is written in code, designed on some other platforms, which are still code anyway. Accordingly, the goal of user experience, and user interface is, basically, to increase the productivity of a given employee when performing some task. That is, its job specifically is to give you convenience, clarity, and help you get some piece of work done as fast as possible. Another aspect that goes a bit deeper is cognitive load. When we talk about cognitive load, we're talking about our so-called working memory. Every person perceives, and everyone has heard this, 7 plus or minus 2 objects at a time. Surely many of you have already encountered this in the context of other subject areas. In our case, same thing. When we look with our eyes, we're not able to take in too many objects, we're not able to take in too many colours, not able to take in some unlimited set of functions, some super-capable thing and so on. So the most-used products you could name right now, and you'll surely agree with me, is Google itself, which has no functions whatsoever compared with, say, Mail.ru, which has probably been around since... By Mail.ru I mean the search engine, which has probably never changed at all since 2005 or so. That is, overload doesn't let you use the search engine effectively, so everyone usually goes either to Google or, these days, accordingly, everyone already works in Yandex. Yandex drew on the experience, the long experience of all search engines, and put it all more or less in order and provides a really quite convenient interface. Accordingly, our job when implementing an interface, and your job when using it, is to find the roughest spots and eliminate them to increase productivity. Now for something a bit more interesting. Gestalt principles are probably not the most common terminology that you come across in relation to user interface and design. These are basically the fundamental principles your understanding is built on, your work, even paperwork. So if we talk about the principle of proximity, about elements placed next to each other, they are perceived as logically related. In the same way, if there's a computer on your desk, say, and a cup with coffee in it, you'll understand that these objects are related. Though logically you'll understand they shouldn't be there together, because that violates safety rules. Accordingly, in an interface, when we work, we always need to take the related components and place them in one area. Here I'll explain, a little digression, why I'm talking about these. Because every time you interact with an interface from now on, it'll be very interesting to apply each of these principles and write to the developer: listen, please change this to that, because these things aren't logically related. The principle of similarity. Colour, shape, whether it's a geometric shape or an organic shape. Many of you've seen this, for example, in the interface of any email client. What's related there? On the left you have the list of messages, on the right the message view. That's exactly what we mean: separate areas are placed in different locations. Likewise, in the tools you use at work, you'll often find there can be, for example, dedicated pages for user settings, dedicated pages for, say, interface settings. Dedicated pages for configuring some other parameters. If you're loading data, a pop-up window will definitely appear, and so on. So through shape, colour and various contrasts we can provide a much clearer understanding of what we're doing right now in our work. Next, regarding the principle of closure. I'll skip it here, it's a bit convoluted, and I'll come back to it in the Q&A section. As for the principle of common fate, the point here is that in every interface everything must happen in a predictable way. There's a, so to speak, a phrase from a certain book: "this button was here the last time I was here." Some of you may have noticed that in web apps, modern ones, the placement of certain components changes very often, and accordingly the layout may change after updates. So after an update you usually don't immediately understand how to perform a particular task. Especially in my case, probably, given my experience in the organisations where I've been, I worked more with American software. Take Google Workspace, it's a set of tools for email, presentations, documents and everything else. When, probably in 2018, they started reworking the workspace they originally had, and around 2020 they released the update, literally everyone, I think, was lost and had no idea whether to keep using it, because the changes were too, were too significant. Yes, so here we're saying that every element should still be preserved: if we've already laid down some particular pattern, that is, a user experience, we absolutely must keep seeing it. And the figure-ground principle is much the same as similarity and proximity, just more, just deeper, let's say. As for, for example, how a user interface can, there's a lot of text here and little meaning, I'll expand on it, how actually a user interface can effectively help perform a specific task. If we, for example, during any incident, we open the logs and, roughly speaking, there's a wall of white lines on black, maybe even without any highlighting, our eyes run over it, we have to read 10,000 lines and, accordingly, well, maybe by the hundredth line our cognitive load, which we talked about, is just so, the brain gets so overloaded with information that you stop, accordingly, taking in any further lines of those same logs, or if you're analysing some tabular data. Now, if instead of that we had an interface that simply indexed at least those logs, and we could specify some concrete points to search for, we would basically cut the work down by tens, if not hundreds of times. So, the second element, what we talked about, figure-ground. If we, accordingly, highlight things in the text with separate colours, red means alerts. If we've taken some pattern and, through rules, programmed it, green is good, orange is moderate, needs attention, red, accordingly, is highlighted, and we see that something is bad. So when we talk about the actual benefit of a user interface, we're talking about how conveniently placed components, conveniently placed elements, properly in the right hierarchy, allow you to take in information much faster. Accordingly, in real life you may encounter a similar, let's say, pattern, if we're talking about a stack of papers. If you bring, say, your boss a stack of papers like this, which sheet will he read first? Accordingly, you need to put the right sheet, the one that you and he, accordingly, care about most, on top. Same thing here. The interface should highlight the key aspects. The interface should highlight the most important details. And now, what I want to say about practical points. This slide will probably be worth photographing for later. But overall, when you now interact with the developers of any product that you encounter, that you work with, be sure to try to pay attention to whether the interface is convenient for you, whether it's actually effective, whether it lets you get the job done. And you can pay attention to each of the points I've listed here. First, regarding unified search. If the platform some vendor has built does have search, ask them to make it a single one. Because the more search engines inside one platform, the harder it is to work. Second, regarding templates and dashboards. Nowadays you absolutely have to build interfaces that let you customize, basically, your work. Because even if you look at your own desktop, at your colleagues' desktops, one likes it here, another likes it there, someone likes two monitors, someone doesn't work with monitors at all. And accordingly, it's the same here. Demand it, ask for it. It's interesting, and it really does improve work efficiency. And be sure to ask for visualization. Statistics, various charts, various links, if you work with some kind of structures, if you work on investigations, if it's searching for affiliated persons or for relationships, some kind of corruption scheme. Hotkeys are probably not the most common way of getting work done in general, but those of you who have used Excel, who use Excel actively, for example, may know about the Alt key, which activates shortcuts that let you perform basic functions much faster, for example sorting data, arranging columns, their sizes, enlarging, shrinking and so on. Knowing them, you simply multiply the efficiency of your work many times over. Clarity and unambiguity — again, it's the Gestalt principles that came up earlier; it's about everything having to be clear. If a button is red, it's most likely delete. If a button is green, it's most likely create. If a button is blue, it's most likely some more or less neutral action or running some operation. Try to pay attention to that too, and don't hesitate to point it out to the developers. And as for feedback, absolutely demand that the system talks to you. If you're working with a software product, you click a button and it complains sort of on the sly, and you don't understand what's going on, be sure to write to the developers saying, listen, it would be great if, when I click this button, it at least showed a spinner. So here I want to stress: formulate and voice your requirements for the interfaces you use. In terms of benefits for business, and for working in agencies in general, a good interface definitely lets you invest more time in the truly key tasks. Surely everyone, or many of you, those who have worked with various technical tools, may remember the evolution from the 2000s to around 2015, when really all the STS, the special technical means — for me the closest example is customs control. Technology is developing very fast and, accordingly, raises labour efficiency, raises the efficiency of individual employees, lets you focus on more interesting and important tasks, the ones our computers and devices can't do yet. Summing up, I'll repeat once more what I want to stress: that users pay more attention to how things should be, that users get involved in this part and remember that you can always get feedback, and try not to put up with people building bad, inconvenient interfaces. That's all. It would be great to discuss any questions, if any come up. Colleagues, your questions. Thank you. — — Right, Alexey. Well, I'll ask one question, as a direct user — not of your interface, but of a rather scary and overloaded one; the cobbler's children go barefoot. So, it was strange not to see — I think I didn't see — an item like customization. Because even a bad, even a clumsily drawn interface — to hell with it, so my button is red, I'll get used to it. It's another matter when I need, for example, the filters arranged in a specific order. To put the ones I need there, not the ones the developer thought most popular, and the column order I want while investigating something in that interface. Again, in 99% of cases some four main columns are enough for me, and I want to hide the rest, or for different data types — a separate set of columns for email, and so on and so forth. So drawing little buttons is great, of course, but unless you're a client with tens of millions a year in support fees, you can only change the colour of the buttons in your imagination, and the developer is unlikely to adapt to you. Yes, that's a very good observation. I'll say two things about it. First. I probably didn't elaborate enough on the templates and dashboards point. That's exactly where I wanted to talk about the ability to adapt the view to the tasks you need. This is precisely about the interface letting the user customize something for themselves on their own. But the second thing I want to say concerns the possibility of customization. Why I'm not exactly against it, but I won't champion this particular idea — because other people may be using the system besides you. Accordingly, one way or another, the user experience, the actual user experience, should be close to uniform, because you have colleagues whose colours and layouts may, accordingly, be different. And if, say, you recolour the buttons — well, buttons are the most basic example, but if we're talking about columns: you set them up your way, did the task, colleagues came and said, look at the second column. His second column is completely different. So with customization, especially in products that are used collaboratively, you need to be very careful, otherwise there's a chance of catching a caveat, so to speak, where problems arise in your communication simply from misunderstanding, if you've really over-customized things in different directions. But overall it's a very valid, very fair remark that the user interface should be highly customizable for the individual. And that's what I wanted to say here. Let's say, in incident investigation, in this respect — if we focus specifically on this — I think this problem is solved by an end-to-end identifier for a piece of intercepted data or whatever, some ID that is simply consistent throughout. So which column is where is basically not a question. And on top of that, it seems to me that generally there are about 10 people on an interface... Oh, not on an interface — on a single incident, some phishing email, there aren't 10 people poring over that email at once. So we'll stock up out there and continue the argument with knives. — — Fine, just please, no blood. At least not today. Any more questions? Anyone? Well, if there are no questions, let's send Nikita off with applause. Nikita, thanks so much. As always, it was great. The mic — and that can stay on the stand. Thank you very much.