Forensics toolkit. Volatility 2/3 command builder, Windows Security Event ID reference with MITRE ATT&CK mapping and Sigma rule generation, and IR Timeline Builder with TTD/TTC/TTR calculation and regulatory deadline verification.
Volatility 2 and 3 side-by-side. Select OS profile, image path, and category (Process Analysis, Network, Registry, Credentials, Filesystem, Malware Hunt, Linux). Generates the full command with explanation and chaining tip.
Essential Windows Event IDs with search, category filters (Authentication, Privilege, Process, Lateral Movement, Defense Evasion...), severity color-coding, MITRE ATT&CK mapping, and one-click Sigma rule skeleton generation.
Incident response timeline with TTD/TTC/TTR calculation and automatic regulatory deadline verification (GDPR Art.33 72h, NIS2 24h/72h/1 month, PCI-DSS). Export report.