Everything GI Forensic Tool does — in one executable.
Browser history, USB device history, Wi-Fi profiles, event logs, network state, and installed-software evidence — collected from a machine you're authorized to examine, then exported as a chain-of-custody PDF in minutes. One portable binary per platform. Windows, macOS, and Linux. No installer.
Built for examiners
A native application window on Windows, no console flashes, on-demand PDF export with a SHA-256 data-set fingerprint and full session audit log — evidence you can hand to a court, not a screenshot.
Nothing leaves the machine
Every collector reads local state only. The one disclosed exception is a same-subnet LAN ping sweep. No telemetry, no cloud upload — the dashboard server only ever binds to 127.0.0.1.
Licensed to verified agencies
Every signup is manually reviewed before approval. This tool can read saved Wi-Fi keys and browser history, so access is gated to law enforcement, government, and registered private investigators — not sold on the open market.
One tool, three operating systems — but not the same on every one
GI runs everywhere. Some artifacts are Windows-specific OS features with no real equivalent elsewhere — that's disclosed here and in the app itself, not glossed over.
| Capability | Windows | macOS | Linux |
|---|---|---|---|
| Native application window | ✓ | — Opens in your browser | — Opens in your browser |
| Full system information (hardware/BIOS/OS build) | ✓ | ✓ | ✓ |
| Installed-software audit (AI / wallet / VM tags) | ✓ | ✓ | ✓ |
| USB device history | ✓ Full history | ~ Currently-attached only | ~ Currently-attached only |
| Live USB-insert detection | ✓ | ✓ | ✓ |
| Account identity (Microsoft / iCloud) | ✓ | ✓ iCloud | ~ GNOME Online Accounts only |
| Device & privacy access log | ✓ | ~ Camera/mic reliable; location best-effort | ~ Flatpak sandbox grants only |
| Execution history (last-run per program) | ✓ incl. Amcache | ✓ | ~ GNOME/Zeitgeist only, best-effort |
| Recent files | ✓ | ~ Best-effort, unverified | ✓ |
| Connection owning process | ✓ | — Needs root | ✓ |
| Browser download history | ✓ | ✓ | ✓ |
| Saved browser passwords, auto-revealed | ✓ Chrome/Edge/Brave/Opera + Firefox | — | — |
| ShellBags, Jump Lists, Office/RDP/Run MRU | ✓ | — | — |
| Recycle Bin / Trash | ✓ Full detail | ~ Listing only, weaker metadata | ✓ Full detail |
| Autostart programs | ✓ Run keys + Startup folders | ✓ LaunchAgents/Daemons | ✓ XDG autostart + systemd + cron |
| Services / drivers inventory | ✓ | — | — |
| Local accounts & admin membership | ✓ | ✓ | ✓ |
| Hosts-file tamper check | ✓ | ✓ | ✓ |
| Audit-log tamper detection | ✓ | — | — |
| Browser history, Wi-Fi, event logs, network, Bluetooth, storage, PDF report | ✓ | ✓ | ✓ |
Full breakdown of every category, including why: see the features page.
15 artifact categories, one dashboard
Overview & system info, browser history (plus downloads and saved passwords), USB device history, folder & app history (ShellBags, Jump Lists, Office/RDP MRU), Recycle Bin/Trash, persistence & local accounts, Wi-Fi profiles, storage, event logs (with audit-log tamper detection), network state (with a hosts-file tamper check), Bluetooth, account identity, privacy & execution history (including Amcache), installed-software audit, and a chain-of-custody PDF export.
Ready to bring GI into your caseload?
Registration takes a few minutes. Your agency is verified by our team before any payment or download link is issued.
Register your agency