Forensics Toolkit

Forensics toolkit. Volatility 2/3 command builder, Windows Security Event ID reference with MITRE ATT&CK mapping and Sigma rule generation, and IR Timeline Builder with TTD/TTC/TTR calculation and regulatory deadline verification.

#Memory Forensics

#Volatility Command Builder

Volatility 2 and 3 side-by-side. Select OS profile, image path, and category (Process Analysis, Network, Registry, Credentials, Filesystem, Malware Hunt, Linux). Generates the full command with explanation and chaining tip.

Volatility Command Builder

Select a command above to see its explanation.

Memory Artifact Quick Reference

Artifact / IOC Vol2 Plugin Vol3 Plugin Notes

#Windows Event Analysis

#Windows Security Event ID Reference

Essential Windows Event IDs with search, category filters (Authentication, Privilege, Process, Lateral Movement, Defense Evasion...), severity color-coding, MITRE ATT&CK mapping, and one-click Sigma rule skeleton generation.

Windows Security Event ID Reference

ID Name Log Description MITRE Severity

#Incident Response

#IR Timeline Builder

Incident response timeline with TTD/TTC/TTR calculation and automatic regulatory deadline verification (GDPR Art.33 72h, NIS2 24h/72h/1 month, PCI-DSS). Export report.

Incident Response Timeline Builder

Add Event

Timeline

No events added yet. Add your first event above.

#Also See

#Cyber Aurelien Guidi