Built for Digital Investigations
Overview & System Info
The command center — case metadata, collection health, and a full hardware/OS fingerprint in one view.
- Case details, collection health, and system info all on one screen.
- A record count for every category, one click from anywhere to jump to it.
- Full make/model, CPU, memory, and OS details for the machine examined.
- A profile of every real user account on the machine, with when it was last used.
Browser History
No row cap on history, plus download records and saved passwords — every visit, every browser, cross-referenced against signed-in accounts.
- Complete browsing history — not just the last few thousand visits.
- Every file downloaded: source URL, where it was saved, and whether it's still there.
- Saved website passwords, decrypted automatically — no extra click needed.
- Search and filter by browser, adult/crypto content, night-time activity, or pages with an email address on them.
- See which signed-in account each browser profile belongs to.
- Visual charts for visits per day, browser usage, and most-visited domains.
USB Device History
Beyond storage vs. other — category detection, cross-run history, and live insert alerts.
- Every USB device identified by type — flash drive, phone, webcam, hardware wallet, and more.
- Know instantly whether a device has been seen on this machine before, and when.
- Get a live alert the moment a new device is plugged in while you're working a case.
- Crypto hardware wallets (Ledger, Trezor, KeepKey) flagged automatically.
Folder & App History
Every folder ever browsed, every file recently opened per app, and every "recently used" registry list Windows keeps — three artifacts most tools treat as separate, unified in one tab.
- Every folder this machine has ever browsed — including folders on a USB drive that's since been unplugged and thrown away.
- Recently opened files, broken out per application.
- Documents opened in Office, commands typed into the Run box, paths typed into Explorer, and servers connected to over RDP.
Recycle Bin / Trash
Original path, deletion time, and size for everything sent to the Recycle Bin or Trash — whether or not it's still recoverable.
- What was deleted, from where, and when — even after the Recycle Bin has been emptied.
- Whether the deleted item is still sitting in the bin, recoverable right now.
Persistence
Where programs launch automatically, every service Windows knows about, and who actually has access to this machine.
- Every program set to launch automatically at logon.
- Every Windows service and driver, flagged when it's running from a suspicious location.
- Every local user account, and who's an administrator.
Wi-Fi Profiles
Every saved network, its access point, and connect/disconnect history — passwords decrypted automatically as soon as the tab loads.
- Every saved Wi-Fi network and its full connect/disconnect history.
- Identifies the exact router each network used.
- Saved passwords decrypted and shown automatically, no extra step required.
Storage Inventory
Every physical disk and volume, capacity used and free, at a glance.
- Every disk and drive on the machine, with capacity used and free.
Windows Event Logs
NirSoft-style event review, filterable in seconds — plus an automatic check for deliberately cleared logs.
- Search and filter system event history in seconds.
- Visual breakdown by severity and top sources.
- An automatic, high-visibility flag if the security audit log was ever cleared.
Network State
Adapters, active connections, a hosts-file tamper check, and the one deliberate, fully-disclosed exception.
- See every active network connection and which program is using it.
- Full network adapter configuration for the machine.
- A tamper check on the hosts file — a common way malware silently redirects a real domain.
- Discover other devices on the same local network.
Bluetooth Devices
Every device this machine has seen or paired with.
- Every Bluetooth device this machine has connected to or seen nearby.
- When each device last connected.
Account Identity
Which cloud account this machine is actually signed into.
- See which Microsoft, Apple, or (on GNOME) online account this machine is signed into.
Privacy & Execution
What the OS itself recorded about device access, and what actually ran.
- See which apps accessed the camera, microphone, or location, and when.
- A history of what actually ran on this machine — on Windows, including a real run count per program.
- Recently opened files and folders.
- macOS location access and recent files are best-effort and unverified against real macOS hardware; Linux privacy/execution coverage is GNOME-specific — see full technical detail for why.
Installed Software Audit
AI tools, crypto wallets, and virtual-machine evidence, layered on top of a real installed-programs inventory on every platform.
- A full inventory of every installed program.
- Automatic flags for AI tools, crypto wallets, and virtualization software.
- Evidence of virtual machines used on this device.
- When each program was last run.
Chain-of-Custody Report
One click, a print-ready report with an integrity fingerprint built in.
- A polished, print-ready PDF report in one click.
- A built-in integrity fingerprint, so the report can't be quietly altered after the fact.
- Clickable links and full-content tables — nothing truncated.
* Two disclosed exceptions, neither during actual case collection: the local network device scan pings addresses on this machine's own subnet (see Network State), and a one-time license activation call on first run or after expiry — every run after that verifies your license completely offline, even air-gapped.