Technical Documentation

Guides and references to execute, parameterize, and export results from each tool.

Guides by Tool

Select the tool to see requirements, installation, execution, parameters, and output.

Analysis Capture

Powerful Artifact Recovery

Recover and analyze digital artifacts from Windows and Linux systems with a focus on speed and portability. Integrates structured export and MITRE ATT&CK mapping.

Key Points

  1. Live or offline acquisition and analysis in a single flow.
  2. Export in JSON, CSV, and HTML ready for reports.
  3. Visual correlation via Chronos — Timeline and Nexus — Graph.
  4. Portable execution without dependencies or installation.
PowerTriage Windows

PowerTriage

PowerShell script for rapid triage on Windows. Extracts artifacts like Amcache, Prefetch, SRUM, and events, with structured export for analysis.

Key Points

  1. Direct execution on computers 10/11/Server or remote.
  2. Quick/Full/Custom mode and offline analysis.
  3. MITRE summary and compatibility with Chronos/Nexus.
  4. Output organized by artifact and chosen format.
PowerTriage Linux

PowerTriage Linux

Standalone Bash tool for triage on Linux. Analyzes logs, sessions, tasks, cron, and persistence artifacts.

Key Points

  1. Support for live analysis and mounted volume.
  2. Export in lightweight formats for reports.
  3. Integration with Chronos/Nexus for visual correlation.
  4. Simple execution with minimal permissions.
PowerTriage IoT

PowerTriage IoT

Specialized version for IoT devices and OpenWRT. Audits configurations, credentials, and critical services.

Key Points

  1. Lightweight modules designed for embedded environments.
  2. Export in compact formats for auditing.
  3. Offline mode and execution on devices with BusyBox.
  4. Results ready for correlation on the platform.
Forge Interface

Forge

Normalization engine that turns raw evidence into structured investigations. Multi-cloud support for AWS, Azure, GCP, and M365.

Key Points

  1. Processes logs from multiple sources (Syslog, EVTX, JSON, CSV).
  2. Normalizes data for ingestion into Chronos and Nexus.
  3. Community Edition focused on AWS CloudTrail.
  4. Pro Edition with full Multi-Cloud support.