DFIR/Investigation Hub
🔬 DFIR Investigation Platform

Investigation
Hub — DFIR Tools

Interactive forensic investigation tools across Windows, Linux, Memory, Evidence, and Malware analysis. Build commands, decode artefacts, look up Event IDs, convert timestamps, and map attack chains — all client-side.

5
Modules
22
Tools
200+
Event IDs
10
TS Formats
100%
Client-Side
🪟

Windows Forensics

Comprehensive Windows investigation toolkit — Event ID reference, artefact finder, registry forensics map, browser artefacts, and timestamp conversion across all 10 forensic formats.

200+ Event IDs Registry Hives Browser Artefacts 10 TS Formats
Windows Investigation Tools
Interactive📋

Windows Event ID Reference

100+ Event IDs, attack indicators, filter by category and severity.

Interactive🗺️

Windows Artefact Finder

Find artefacts by investigation goal — lateral movement, persistence, exfil.

Reference🗝️

Registry Forensics Map

ShimCache, UserAssist, Run keys, SAM, NTUSER.DAT — full registry forensics.

Reference🌐

Browser Forensics

Chrome, Firefox, Edge artefacts — history DB paths, tables, columns.

Interactive⏱️

Timestamp Converter

Convert between 10 forensic timestamp formats — FILETIME, Unix, LDAP, FAT.

🐧

Linux Forensics

Linux investigation reference covering critical log paths, live response commands, persistence mechanisms, and forensic artefact locations for Ubuntu, CentOS, RHEL, and Debian.

Log Paths Live Response Persistence Audit Framework
Linux Investigation Tools
Reference📁

Linux Log Path Reference

Critical log locations, syslog, auth, kern, audit — with evidence value for each.

Interactive

Linux Live Response Builder

Build targeted bash live response commands for triage, persistence, network.

Reference🔗

Linux Persistence Mechanisms

Cron, systemd, rc.local, LD_PRELOAD, bashrc backdoors — IOCs and detection.

Interactive🔍

Auditd Rule Builder

Generate auditd rules for syscall monitoring, file access, and privilege changes.

🧠

Memory Forensics

Memory investigation toolkit — Volatility 3 command builder, process injection pattern identifier, YARA rule generator, and memory artefact reference for Windows and Linux.

Volatility 3 Injection Patterns YARA Builder Artefact Map
Memory Investigation Tools
Interactive💾

Volatility 3 Command Builder

Build Volatility 3 commands by objective — processes, network, injection, creds.

Interactive💉

Process Injection Identifier

Enter process details — identify process hollowing, DLL injection, reflective loading.

Interactive🎯

YARA Rule Builder

Generate YARA rules from strings, hex patterns, and PE metadata indicators.

Reference🗺️

Memory Artefact Reference

Key memory structures — PEB, TEB, VAD tree, EPROCESS, loaded modules map.

🔒

Evidence & Timeline

Forensic evidence management tools — chain of custody tracker, file hash verifier, super-timeline builder command generator, and evidence acquisition checklist.

Chain of Custody Hash Verification Super-Timeline Acquisition
Evidence Tools
Interactive📝

Chain of Custody Generator

Generate a complete chain of custody record for digital evidence items.

Interactive🔢

Evidence Hash Verifier

Verify MD5/SHA1/SHA256 hash pairs and generate hash verification reports.

Interactive📅

Super-Timeline Builder

Generate log2timeline / Plaso commands for full forensic super-timeline creation.

Reference💿

Evidence Acquisition Checklist

Live acquisition order, disk imaging commands, write-blocker guidance.

🦠

Malware Analysis

Static and dynamic malware analysis tools — PE header inspector, sandbox IOC decoder, base64/hex string decoder, packer identifier, and malware family quick-reference.

Static Analysis IOC Decoder String Analysis Packer ID Family Reference
Malware Analysis Tools
Interactive🔬

Static Analysis Checklist

Step-by-step PE static analysis — imports, sections, strings, entropy, packer check.

Interactive🔍

Sandbox IOC Parser

Paste sandbox report text — extract and categorise IPs, domains, hashes, registry keys.

Interactive🔓

String / Shellcode Decoder

Decode Base64, XOR, hex, URL-encode, rot13, and PowerShell encoded commands.

Reference📦

Packer & Obfuscation Reference

UPX, MPRESS, Themida, .NET obfuscators — indicators and unpacking approaches.

Reference👾

Malware Family Quick Reference

Ransomware, RATs, stealers, loaders — IOCs, C2 patterns, MITRE techniques.

🔬

Tool