Knowledge Base
Browse forensic artifacts and investigation blockers. Your reference library for DFIR evidence sources, tools, and pivot strategies.
Forensic Artifacts
286 artifacts across 7 platforms
Comprehensive reference for forensic evidence sources including file locations, forensic value, required tools, and collection procedures.
61Windows41Linux35macOS60Cloud & SaaS22Network33iOS34Android
Investigation Blockers
21 common obstacles with pivot strategies
When your investigation hits a wall, find the matching blocker for signals, pivot actions, and alternate evidence sources.
No EDR Agent on Compromised Hosts
Critical Logs Rotated/Overwritten Before Collection
BitLocker/Encrypted Drives Preventing Forensic Imaging
No PCAP or NetFlow Data Available
+17 more
Artifact Categories
View allAuthentication & Access
33Execution Evidence
34Persistence Mechanisms
23Filesystem & Timeline
20User Activity
35System Configuration
35Memory & Live State
8Email Security
5Identity & Directory
10Cloud Infrastructure
16Data Access & Storage
8Network Traffic
19Perimeter Security
6DNS Analysis
5Communication
14Location Data
9Web Activity
6