A professional-grade forensics toolkit for investigators, security analysts, and researchers. Analyze memory dumps, network captures, event logs, and detect malware โ all from one unified interface.
[INFO] Loading case: CASE-2024-0042
[INFO] Memory image: dump.raw (4096 MB)
[INFO] Processes found: 47
[ALERT] Suspicious process: mimikatz.exe (PID 3842)
[INFO] Network connections: 312 packets
[ALERT] C2 traffic detected โ 185.220.101.x
[INFO] YARA scan: 3 threats / 1,204 files
[INFO] Generating PDF report... Done
โ
Every forensic module in a single unified Qt6 application. No switching between tools.
Connect GPT-4, Claude, or local Ollama models to automatically analyze evidence and generate investigation summaries.
Export findings as professional PDF, HTML, or JSON reports with chain-of-custody, case metadata, and executive summaries.
MD5, SHA-1, SHA-256 hashing with OpenSSL. Verify evidence integrity throughout the investigation lifecycle.
Load custom YARA rule sets for malware detection. Built-in heuristics catch packed PEs, shellcode, and extension mismatches.
Native PCAP parser reconstructs TCP streams, DNS queries, HTTP sessions, and flags suspicious C2 traffic patterns.
Recursive directory scanning with MIME detection, hidden file discovery, duplicate detection by hash, and full metadata extraction.
Create cryptographic baselines and detect modified, added, or deleted files. Track tampered evidence across time.
Parse raw memory dumps to extract running processes, loaded DLLs, network connections, and ASCII/Unicode strings.
Native PCAP parser with Ethernet/IPv4/TCP/UDP/DNS/HTTP dissection. Reconstructs sessions and identifies suspicious hosts.
Parse Windows EVTX exports for failed logins, USB insertions, process executions, and security audit events.
YARA-based scanning engine with built-in heuristics for shellcode, packed PEs, and extension mismatches.
Connects to OpenAI, Anthropic, OpenRouter, or local Ollama. Generates structured investigation reports mapped to MITRE ATT&CK.
Export complete case findings as PDF (printer-quality), HTML, or machine-readable JSON with full case metadata.
SQLite-backed case database. Track investigators, evidence chain-of-custody, case status, and all analysis results per case.
Free and open source. No registration. No limits.
Windows 10/11 ยท 64-bit ยท Free forever