Investigation
Hub — DFIR Tools
Interactive forensic investigation tools across Windows, Linux, Memory, Evidence, and Malware analysis. Build commands, decode artefacts, look up Event IDs, convert timestamps, and map attack chains — all client-side.
Windows Forensics
Comprehensive Windows investigation toolkit — Event ID reference, artefact finder, registry forensics map, browser artefacts, and timestamp conversion across all 10 forensic formats.
Windows Event ID Reference
100+ Event IDs, attack indicators, filter by category and severity.
Windows Artefact Finder
Find artefacts by investigation goal — lateral movement, persistence, exfil.
Registry Forensics Map
ShimCache, UserAssist, Run keys, SAM, NTUSER.DAT — full registry forensics.
Browser Forensics
Chrome, Firefox, Edge artefacts — history DB paths, tables, columns.
Timestamp Converter
Convert between 10 forensic timestamp formats — FILETIME, Unix, LDAP, FAT.
Linux Forensics
Linux investigation reference covering critical log paths, live response commands, persistence mechanisms, and forensic artefact locations for Ubuntu, CentOS, RHEL, and Debian.
Linux Log Path Reference
Critical log locations, syslog, auth, kern, audit — with evidence value for each.
Linux Live Response Builder
Build targeted bash live response commands for triage, persistence, network.
Linux Persistence Mechanisms
Cron, systemd, rc.local, LD_PRELOAD, bashrc backdoors — IOCs and detection.
Auditd Rule Builder
Generate auditd rules for syscall monitoring, file access, and privilege changes.
Memory Forensics
Memory investigation toolkit — Volatility 3 command builder, process injection pattern identifier, YARA rule generator, and memory artefact reference for Windows and Linux.
Volatility 3 Command Builder
Build Volatility 3 commands by objective — processes, network, injection, creds.
Process Injection Identifier
Enter process details — identify process hollowing, DLL injection, reflective loading.
YARA Rule Builder
Generate YARA rules from strings, hex patterns, and PE metadata indicators.
Memory Artefact Reference
Key memory structures — PEB, TEB, VAD tree, EPROCESS, loaded modules map.
Evidence & Timeline
Forensic evidence management tools — chain of custody tracker, file hash verifier, super-timeline builder command generator, and evidence acquisition checklist.
Chain of Custody Generator
Generate a complete chain of custody record for digital evidence items.
Evidence Hash Verifier
Verify MD5/SHA1/SHA256 hash pairs and generate hash verification reports.
Super-Timeline Builder
Generate log2timeline / Plaso commands for full forensic super-timeline creation.
Evidence Acquisition Checklist
Live acquisition order, disk imaging commands, write-blocker guidance.
Malware Analysis
Static and dynamic malware analysis tools — PE header inspector, sandbox IOC decoder, base64/hex string decoder, packer identifier, and malware family quick-reference.
Static Analysis Checklist
Step-by-step PE static analysis — imports, sections, strings, entropy, packer check.
Sandbox IOC Parser
Paste sandbox report text — extract and categorise IPs, domains, hashes, registry keys.
String / Shellcode Decoder
Decode Base64, XOR, hex, URL-encode, rot13, and PowerShell encoded commands.
Packer & Obfuscation Reference
UPX, MPRESS, Themida, .NET obfuscators — indicators and unpacking approaches.
Malware Family Quick Reference
Ransomware, RATs, stealers, loaders — IOCs, C2 patterns, MITRE techniques.