Forensic Analysis.
Know Your Artifacts.
Registry persistence lookup, memory forensics, and disk artifact analysis: structured forensic workflows for incident response. ARTIFEKTX is a fast, on-the-go reference for Windows artifacts; CHRONIFY converts between every timestamp format you'll hit during timeline analysis; WIN-EVT is the deep-dive reference for Windows Event IDs. More tools land here as they're ready.
PARTIAL
//
TOOLS
ARTIFEKTX
Windows DFIR Artifact Reference
Fast, on-the-go reference for Windows forensic artifacts: registry hives, execution evidence, persistence, browser activity, memory, network, and event logs. What each one records, what normal looks like, and what to flag.
LAUNCH ARTIFEKTX →
CHRONIFY
Forensic Timestamp Converter
Convert between every timestamp format you'll hit in DFIR work: Unix, Windows FILETIME, .NET Ticks, Chrome/WebKit, Mac Absolute, HFS+, DOS, Excel/OLE, Julian, GPS, RFC 2822. Single-value sync, direct format-to-format, batch lists, and a duration calculator.
LAUNCH CHRONIFY →
WIN-EVT
Windows Event ID Reference
Deep-dive reference for Windows Event IDs SOC analysts triage daily: annotated sample logs, attack-scenario examples, key-field breakdowns, investigation steps, false positives, and MITRE ATT&CK mapping across Security, PowerShell, and Sysmon logs.
LAUNCH WIN-EVT →