SOC alert triage and investigation guidance. Paste an alert description and observables to get structured investigation steps, hypothesis generation, and recommended queries for your SIEM/EDR.
Generate a comprehensive DFIR incident report by consolidating findings from all analysis skills (memory, disk, network, log, malware, IOCs, timeline). Produces an executive and technical report.
Analyze disk images and filesystem artifacts using Sleuthkit (mmls, fls, icat), binwalk, strings, and bulk_extractor. Recover deleted files, build timelines, and examine partition structures.
Acquire and preserve digital evidence following forensic best practices. Disk imaging, memory capture, log collection, and chain of custody documentation. Inspired by SIFT workstation methodology.
Extract, deduplicate, and classify Indicators of Compromise (IOCs) from any evidence source — files, logs, memory dumps, PCAPs, reports, or pasted text. Outputs structured IOC lists in multiple formats.
Analyze system and security logs (auth.log, syslog, Windows EVTX, Apache/Nginx, JSON logs). Detect brute force, lateral movement, privilege escalation, and anomalous activity.
Perform static analysis and triage of suspicious files. Extract hashes, strings, metadata, PE headers, ELF info, embedded URLs, and indicators using strings, file, exiftool, readelf, objdump, radare2, and binwalk.
Analyze memory dumps using Volatility 3 and strings. Enumerate processes, network connections, injected code, and suspicious artifacts from RAM captures.