H3AD-DF
DIGITAL FORENSICS MODULE
by H3AD

Forensic Analysis.
Know Your Artifacts.

Registry persistence lookup, memory forensics, and disk artifact analysis: structured forensic workflows for incident response. ARTIFEKTX is a fast, on-the-go reference for Windows artifacts; CHRONIFY converts between every timestamp format you'll hit during timeline analysis; WIN-EVT is the deep-dive reference for Windows Event IDs. More tools land here as they're ready.

PARTIAL // ARTIFEKTX + CHRONIFY + WIN-EVT LIVE · MORE TOOLS COMING
AX
ARTIFEKTX
Windows DFIR Artifact Reference
LIVE
Fast, on-the-go reference for Windows forensic artifacts: registry hives, execution evidence, persistence, browser activity, memory, network, and event logs. What each one records, what normal looks like, and what to flag.
134 ARTIFACTS · ATT&CK MAPPED · ANOMALY CALLOUTS
LAUNCH ARTIFEKTX →
CY
CHRONIFY
Forensic Timestamp Converter
LIVE
Convert between every timestamp format you'll hit in DFIR work: Unix, Windows FILETIME, .NET Ticks, Chrome/WebKit, Mac Absolute, HFS+, DOS, Excel/OLE, Julian, GPS, RFC 2822. Single-value sync, direct format-to-format, batch lists, and a duration calculator.
16 FORMATS · 4 MODES · BATCH + DIRECT CONVERT
LAUNCH CHRONIFY →
WE
WIN-EVT
Windows Event ID Reference
LIVE
Deep-dive reference for Windows Event IDs SOC analysts triage daily: annotated sample logs, attack-scenario examples, key-field breakdowns, investigation steps, false positives, and MITRE ATT&CK mapping across Security, PowerShell, and Sysmon logs.
73 EVENT IDS · KQL DETECTION QUERIES · ATT&CK MAPPED
LAUNCH WIN-EVT →