GLOBE//INTELL

Built for Digital Investigations

15Artifact categories
0Network calls during case collection*
3Platforms (Win/macOS/Linux)
1-clickChain-of-custody PDF

Overview & System Info

The command center — case metadata, collection health, and a full hardware/OS fingerprint in one view.

Windows macOS Linux
  • Case details, collection health, and system info all on one screen.
  • A record count for every category, one click from anywhere to jump to it.
  • Full make/model, CPU, memory, and OS details for the machine examined.
  • A profile of every real user account on the machine, with when it was last used.
Full technical sourcing detail (exactly which registry keys, files, and commands each artifact comes from, plus every caveat) is available to licensed agencies. Register your agency or log in.

Browser History

No row cap on history, plus download records and saved passwords — every visit, every browser, cross-referenced against signed-in accounts.

Windows macOS Linux
  • Complete browsing history — not just the last few thousand visits.
  • Every file downloaded: source URL, where it was saved, and whether it's still there.
  • Saved website passwords, decrypted automatically — no extra click needed.
  • Search and filter by browser, adult/crypto content, night-time activity, or pages with an email address on them.
  • See which signed-in account each browser profile belongs to.
  • Visual charts for visits per day, browser usage, and most-visited domains.
Full technical sourcing detail (exactly which registry keys, files, and commands each artifact comes from, plus every caveat) is available to licensed agencies. Register your agency or log in.

USB Device History

Beyond storage vs. other — category detection, cross-run history, and live insert alerts.

Windows macOS Linux
  • Every USB device identified by type — flash drive, phone, webcam, hardware wallet, and more.
  • Know instantly whether a device has been seen on this machine before, and when.
  • Get a live alert the moment a new device is plugged in while you're working a case.
  • Crypto hardware wallets (Ledger, Trezor, KeepKey) flagged automatically.
Full technical sourcing detail (exactly which registry keys, files, and commands each artifact comes from, plus every caveat) is available to licensed agencies. Register your agency or log in.

Folder & App History

Every folder ever browsed, every file recently opened per app, and every "recently used" registry list Windows keeps — three artifacts most tools treat as separate, unified in one tab.

Windows macOS (n/a) Linux (n/a)
  • Every folder this machine has ever browsed — including folders on a USB drive that's since been unplugged and thrown away.
  • Recently opened files, broken out per application.
  • Documents opened in Office, commands typed into the Run box, paths typed into Explorer, and servers connected to over RDP.
Full technical sourcing detail (exactly which registry keys, files, and commands each artifact comes from, plus every caveat) is available to licensed agencies. Register your agency or log in.

Recycle Bin / Trash

Original path, deletion time, and size for everything sent to the Recycle Bin or Trash — whether or not it's still recoverable.

Windows macOS Linux
  • What was deleted, from where, and when — even after the Recycle Bin has been emptied.
  • Whether the deleted item is still sitting in the bin, recoverable right now.
Full technical sourcing detail (exactly which registry keys, files, and commands each artifact comes from, plus every caveat) is available to licensed agencies. Register your agency or log in.

Persistence

Where programs launch automatically, every service Windows knows about, and who actually has access to this machine.

Windows macOS Linux
  • Every program set to launch automatically at logon.
  • Every Windows service and driver, flagged when it's running from a suspicious location.
  • Every local user account, and who's an administrator.
Full technical sourcing detail (exactly which registry keys, files, and commands each artifact comes from, plus every caveat) is available to licensed agencies. Register your agency or log in.

Wi-Fi Profiles

Every saved network, its access point, and connect/disconnect history — passwords decrypted automatically as soon as the tab loads.

Windows macOS Linux
  • Every saved Wi-Fi network and its full connect/disconnect history.
  • Identifies the exact router each network used.
  • Saved passwords decrypted and shown automatically, no extra step required.
Full technical sourcing detail (exactly which registry keys, files, and commands each artifact comes from, plus every caveat) is available to licensed agencies. Register your agency or log in.

Storage Inventory

Every physical disk and volume, capacity used and free, at a glance.

Windows macOS Linux
  • Every disk and drive on the machine, with capacity used and free.
Full technical sourcing detail (exactly which registry keys, files, and commands each artifact comes from, plus every caveat) is available to licensed agencies. Register your agency or log in.

Windows Event Logs

NirSoft-style event review, filterable in seconds — plus an automatic check for deliberately cleared logs.

Windows macOS Linux
  • Search and filter system event history in seconds.
  • Visual breakdown by severity and top sources.
  • An automatic, high-visibility flag if the security audit log was ever cleared.
Full technical sourcing detail (exactly which registry keys, files, and commands each artifact comes from, plus every caveat) is available to licensed agencies. Register your agency or log in.

Network State

Adapters, active connections, a hosts-file tamper check, and the one deliberate, fully-disclosed exception.

Windows macOS Linux
  • See every active network connection and which program is using it.
  • Full network adapter configuration for the machine.
  • A tamper check on the hosts file — a common way malware silently redirects a real domain.
  • Discover other devices on the same local network.
Full technical sourcing detail (exactly which registry keys, files, and commands each artifact comes from, plus every caveat) is available to licensed agencies. Register your agency or log in.

Bluetooth Devices

Every device this machine has seen or paired with.

Windows macOS Linux
  • Every Bluetooth device this machine has connected to or seen nearby.
  • When each device last connected.
Full technical sourcing detail (exactly which registry keys, files, and commands each artifact comes from, plus every caveat) is available to licensed agencies. Register your agency or log in.

Account Identity

Which cloud account this machine is actually signed into.

Windows macOS Linux
  • See which Microsoft, Apple, or (on GNOME) online account this machine is signed into.
Full technical sourcing detail (exactly which registry keys, files, and commands each artifact comes from, plus every caveat) is available to licensed agencies. Register your agency or log in.

Privacy & Execution

What the OS itself recorded about device access, and what actually ran.

Windows macOS Linux
  • See which apps accessed the camera, microphone, or location, and when.
  • A history of what actually ran on this machine — on Windows, including a real run count per program.
  • Recently opened files and folders.
  • macOS location access and recent files are best-effort and unverified against real macOS hardware; Linux privacy/execution coverage is GNOME-specific — see full technical detail for why.
Full technical sourcing detail (exactly which registry keys, files, and commands each artifact comes from, plus every caveat) is available to licensed agencies. Register your agency or log in.

Installed Software Audit

AI tools, crypto wallets, and virtual-machine evidence, layered on top of a real installed-programs inventory on every platform.

Windows macOS Linux
  • A full inventory of every installed program.
  • Automatic flags for AI tools, crypto wallets, and virtualization software.
  • Evidence of virtual machines used on this device.
  • When each program was last run.
Full technical sourcing detail (exactly which registry keys, files, and commands each artifact comes from, plus every caveat) is available to licensed agencies. Register your agency or log in.

Chain-of-Custody Report

One click, a print-ready report with an integrity fingerprint built in.

Windows macOS Linux
  • A polished, print-ready PDF report in one click.
  • A built-in integrity fingerprint, so the report can't be quietly altered after the fact.
  • Clickable links and full-content tables — nothing truncated.
Full technical sourcing detail (exactly which registry keys, files, and commands each artifact comes from, plus every caveat) is available to licensed agencies. Register your agency or log in.

* Two disclosed exceptions, neither during actual case collection: the local network device scan pings addresses on this machine's own subnet (see Network State), and a one-time license activation call on first run or after expiry — every run after that verifies your license completely offline, even air-gapped.

See it running your own caseload

Register your agency