Guides and references to execute, parameterize, and export results from each tool.
Select the tool to see requirements, installation, execution, parameters, and output.
Recover and analyze digital artifacts from Windows and Linux systems with a focus on speed and portability. Integrates structured export and MITRE ATT&CK mapping.
JSON, CSV, and HTML ready for reports.
PowerShell script for rapid triage on Windows. Extracts artifacts like Amcache, Prefetch, SRUM, and events, with structured export for analysis.
Quick/Full/Custom mode and offline analysis.
Standalone Bash tool for triage on Linux. Analyzes logs, sessions, tasks, cron, and persistence artifacts.
Specialized version for IoT devices and OpenWRT. Audits configurations, credentials, and critical services.
Normalization engine that turns raw evidence into structured investigations. Multi-cloud support for AWS, Azure, GCP, and M365.