The standalone investigation toolbox

ThreatResponder Forensics

From artifacts to answers.
Follow the evidence.

Investigate live or offline systems, disk images, memory dumps, artifact folders and external logs. Pivot into specialized analyzers for memory, registry, filesystem, network, scripts, documents and executables — and turn everything into a clear investigation story, findings, timeline and threat detections.

Free for personal, non-commercial use.
Paid licensing for companies and commercial use.

  • Live systems
  • Disk images
  • Memory dumps
  • Artifact folders
  • External logs
Illustrative investigation: follow a suspicious document to its embedded script, memory evidence and network activity, then correlate the findings into an investigation story.
Illustrative investigation

01 / Evidence sources

Create an investigation
from any starting point.

Acquire evidence from running systems, offline images, memory, collected artifacts and external logs.

Live system

Examine a running system and collect the artifacts relevant to your investigation.

Windows endpoint

Disk image

Investigate an offline drive or virtual machine without booting the suspect system.

E01 · VMDK · VHD/VHDX · RAW/DD/IMG · AD1

Memory image

Look for processes, connections and evidence that may never have reached disk.

Raw memory · VMEM · VMRS

Artifact collection

Bring collected evidence into an investigation and continue with specialist analysis.

TRF Collector · KAPE · folders

External logs

Add context from supported external log sources to the endpoint investigation.

Firewall · VPN · identity · endpoint
Illustration of a new investigation with five evidence sources. Red connectors highlight fast triage or full collection, profile-driven acquisition, and one workbench for mixed evidence.

Flexible by design

Start with what you have. Move from triage to deep analysis without changing tools.

Depth out of the box

Prebuilt artifact profiles bring breadth and depth to every investigation.

Built for real-world investigations

A unified workflow for endpoints, images, memory, artifacts and external data.

ThreatResponder Forensics

From analysis to the attack story

View the timeline, reconstruct processes, correlate users and activity,
and assemble the investigation story.

Illustrative Forensics Analyzer workspace with the ThreatResponder Forensics logo: a timeline connects summary findings, process reconstruction, investigation story and network evidence. The sidebar spans execution proof, scripts, event logs, filesystem activity, file access, devices, network activity, inventory, installed applications, registry recovery, accounts, persistence, MFT, USN Journal and $LogFile.

Ask deeper questions

Hunt across execution, scripts, files, network activity and persistence with focused queries and reusable filters. Keep the supporting source records within reach.

Connect the dots

Reconstruct process trees and sessions. Correlate users, systems, file access and network activity on a common timeline to reveal how the attack developed.

Build the story with confidence

Review detections with ATT&CK context, assemble chapters and analyst notes, and export evidence-backed findings for reporting and handoff.

02 / Go deeper

Specialist tools.
One connected investigation.

Move from one evidence type to another through specialized analyzers.
Follow every lead within your investigation.

Pivot across analyzers

Follow the evidence where it leads.

Keep investigation context

Connect related evidence across specialist tools.

Inspect artifacts deeply

Go beyond the overview with specialized analysis.

Built for real investigations

Purpose-built tools for the questions behind the evidence.

03 / Memory Forensics

Memory forensics
that surfaces
what matters

Recover hidden evidence from memory images, then pivot into the artifacts, registry, processes and binaries that help explain what happened.

  • Choose your analysis depth

    Move from focused triage to a fuller memory examination.

  • Automatic threat detection

    Surface hidden processes, suspicious code and memory YARA findings.

  • Process tree reconstruction

    Understand parent–child relationships and investigate anomalies.

  • Recovered network connections

    Connect external activity to the processes behind it.

  • Registry + PE pivots

    Open recovered hives and process executables in specialist analyzers.

View Memory Forensics in action

Memory Forensics — actual product interface showing image assessment, suspicious processes and memory findings.

ThreatResponder Forensics memory assessment: a compromised image, process tree, suspicious-process findings and recovered network connections.

04 / Scripts, traffic & binaries

Deep analysis.
Clearer answers

Decode the script. Trace the traffic. Inspect the binary.

Uncover hidden instructions, reconstruct network activity and examine suspicious executables. Follow recovered payloads into the next analyzer to understand what they reveal.

Script Analyzer

Reveal what the code is hiding.

Illustrative Script Analyzer: decoded layers, recovered PowerShell content and download-behavior findings.
  • Deobfuscation

    Decode and simplify layered scripts.

  • Hidden content

    Identify encoded regions and explore decoded layers.

  • Suspicious behavior

    Review behavior and findings without running the script.

  • Extracted indicators

    Follow recovered URLs, domains and payloads.

Explore Script Analyzer

Examine PowerShell, JavaScript and VBScript in a focused analysis workspace. Review encoded regions and decoded content together, so the original evidence stays in view.

  • Automatically identify encoded regions and attempt to decode them into a navigable layer tree.
  • Review behavior verdicts, confidence, extracted indicators and ATT&CK mappings without executing the script.
  • Go deeper with encoding detection, Base64, hex, XOR and a scratchpad; send recovered executables directly to PE Analyzer.

Next pivotFrom an encoded command to readable content and investigation leads.

Inside this module
  • PowerShell
  • JavaScript
  • VBScript
  • Encoded regions
  • Decoded layers
  • URLs & indicators
  • Behavior mappings

PCAP Analyzer

Follow the traffic. Recover the evidence.

Illustrative PCAP Analyzer: network flows, an HTTP transfer and a recovered script ready for deeper analysis.
  • Visual correlation

    Connect related traffic into an investigation story.

  • Endpoints and flows

    See who communicated, when and over which protocols.

  • Recovered payloads

    Inspect HTTP artifacts and pivot into scripts or binaries.

  • Packet-level detail

    Explore packets, DNS and TLS metadata behind each lead.

Explore PCAP Analyzer

Inspect a packet capture as conversations, protocols and individual packets. Connect network behavior with domains, requests and artifacts recovered from the traffic.

  • Review flows, endpoints, DNS queries, HTTP activity and TLS metadata.
  • Move from a conversation to decoded packet layers and payload detail.
  • Inspect carved artifacts and send relevant files into the specialist analyzers.

See the conversation

Explore endpoints, protocol composition, flows, DNS, HTTP and TLS certificates. Move from the overall capture into a single stream, decoded packet or point on the timeline.

Recognize the pattern

Review detections for suspicious staging, command-and-control behavior, beaconing, tunneling and exposed credentials. Correlation stories group related activity and retain the evidence behind each finding.

Recover the payload

Inspect artifacts carved from available traffic, including HTTP bodies, scripts and executable content. Review hashes and extracted indicators, then continue into Script Analyzer or PE Analyzer.

Hunt and validate

Narrow the capture with focused hunts and saved queries. Pivot between findings, flows, packets, artifacts and timeline entries to check the sequence and explain why an observation matters.

Next pivotFrom a network conversation to the file it carried.

Inside this module
  • Network flows
  • DNS
  • HTTP requests
  • TLS metadata
  • Packet layers
  • Carved files
  • Transferred scripts

PE Analyzer

Understand the signals inside the binary.

Illustrative PE Analyzer: suspicious executable assessment, signing information, YARA matches, section entropy and ATT&CK context.
  • Malware assessment

    Bring YARA and machine-learning findings into view.

  • Structure and entropy

    Inspect sections, imports and signs of packing.

  • ATT&CK context

    Connect suspicious capabilities to adversary techniques.

  • Signatures and indicators

    Review signing information, strings and file metadata.

Explore PE Analyzer

Inspect Windows executables, libraries and drivers with static analysis. Combine structure, signing information, imports, strings and detection results to decide what deserves a closer look.

  • Review PE headers, sections, imports and exports.
  • Examine signatures, entropy and YARA or machine-learning findings.
  • Use the combined evidence to investigate suspicious capabilities and related ATT&CK behavior.

Next pivotFrom a suspicious binary to the evidence behind its assessment.

Inside this module
  • EXE · DLL · SYS
  • PE headers
  • Sections
  • Imports & exports
  • Signatures
  • Entropy
  • YARA
  • Machine learning

05 / Registry & file-system evidence

Deeper evidence. Clearer answers.

Registry Explorer

Explore live and preserved hives. Reveal the history within.

Illustrative Registry Explorer with multiple loaded hives, a registry tree and value table, transaction history, bookmarks and threat findings.
  • Live & preserved hives

    Browse live snapshots, acquired hives and backups together.

  • Transaction-log replay

    Reconstruct available states and follow registry changes.

  • Deleted-value recovery

    Recover deleted entries where evidence survives.

  • Forensic bookmarks

    Save key locations and return to important findings.

  • Artifact views

    Explore persistence, user activity and device history.

  • Threat findings

    Review suspicious keys and values with detection context.

Explore Registry Explorer

Investigate live registry hives through a consistent system snapshot, or open preserved hive files from forensic acquisitions and backups. Keep multiple hives in one workspace and move between their raw structure, interpreted artifacts and threat findings.

  • Inspect several hives together, including system and user hives, with read-only browsing, typed values and raw-byte detail.
  • Replay available transaction logs to reconstruct registry states and examine added, modified or deleted entries.
  • Recover deleted values where evidence remains, search keys and values, and bookmark important locations.
  • Review suspicious keys, values and persistence patterns with rule context, severity and the registry location behind each finding.

Start with meaningful artifacts

Review autoruns, services, scheduled-task cache, Winlogon, COM overrides and shell extensions alongside application history, USB devices, network configuration and per-user activity. Drill into the underlying key whenever a finding needs validation.

Examine the changes that survive

Use transaction-log replay and the history view to inspect available registry states. Follow changes to keys and values, and examine recoverable deleted data. The available history depends on the hive and transaction logs preserved with it.

Keep the investigation organized

Work with SYSTEM, SOFTWARE, SAM, SECURITY, NTUSER.DAT and UsrClass.dat in a shared view. Search and bookmark relevant locations, inspect memory-recovered hives, and export selected findings for reporting or deeper analysis.

Next pivotFrom a suspicious entry to its raw value, recorded history and related artifact.

Inside this module
  • Live & offline hives
  • Multiple hives
  • Transaction-log replay
  • Deleted values
  • Bookmarks
  • Artifact views
  • Threat detections
  • Hex inspection
  • Memory-recovered hives

File System Explorer

Explore disks and images. Recover what remains.

Illustrative File System Explorer showing deleted-file recovery candidates, a volume and folder tree, and recovery progress.
  • Disk image parsing

    Open supported forensic images and live disks.

  • Alternate data streams

    Inspect and extract hidden NTFS data streams.

  • Volume shadow copies

    Explore available snapshots and earlier file versions.

  • Deleted-file recovery

    Assess recoverability and restore available file content.

  • Files & metadata

    Browse folders, inspect timestamps and extract evidence.

  • Flexible source access

    Work with physical disks, local volumes and dynamic volumes.

Explore File System Explorer

Examine file-system structures and the metadata behind the files. Review deleted entries, alternate data streams and available shadow copies alongside the current contents of a volume.

  • Browse raw NTFS structures and inspect file records, timestamps and streams.
  • Review deleted-file candidates and recover content where the underlying data remains available.
  • Use MFT, USN Journal and $LogFile evidence to investigate changes over time.

Next pivotFrom a file record to its changes, origin and recoverable content.

Inside this module
  • MFT records
  • USN Journal
  • $LogFile
  • Alternate data streams
  • Deleted files
  • Shadow copies
  • Recycle Bin
  • Mark-of-the-Web

Image formats

VMDK · VHD · VHDX · EWF/E01 · RAW/DD/IMG · AD1

File systems

NTFS · FAT12 · FAT16 · FAT32 · exFAT

Disk & volume sources

Physical disks, local volumes and Windows dynamic volumes.

Additional access

Volume Shadow Copies and BitLocker unlocking with a 48-digit recovery password.

06 / Logs & documents

Event Logs Analyzer & Document Analyzer

Investigate Windows event evidence and inspect suspicious documents — from detections and timelines to active content and extracted payloads.

Event Logs Analyzer

Search, correlate and detect across Windows event evidence.

  • EVTX
  • Sigma
  • ATT&CK
Illustrative Event Logs Analyzer showing an event timeline, Windows log records and views for detections, sessions, processes and network activity.
  • Windows event evidence

    Investigate Security, System, PowerShell, Sysmon and other event sources.

  • Timeline & focused search

    Filter large event sets and follow the sequence around a finding.

  • Sigma detections

    Review rule matches with severity and the events behind them.

  • Sessions & activity

    Connect logon sessions, process execution and related network events.

  • ATT&CK context

    Map detections to adversary behavior and validate the supporting records.

Explore Event Logs Analyzer

Search Windows events, investigate detections and reconstruct sessions. Time, source and event detail keep the raw records close to the behavior they describe.

  • Filter Security, System, PowerShell, Sysmon and other Windows event sources.
  • Review Sigma detections with severity and MITRE ATT&CK context.
  • Rebuild logon activity and use timelines to examine what happened before and after a finding.

Next pivotFrom a detection to the events and session that support it.

Inside this module
  • Security events
  • System & Application
  • PowerShell
  • Sysmon
  • Windows Defender
  • Task Scheduler
  • Logon sessions
  • Sigma detections

Document Analyzer

Inspect suspicious documents and uncover embedded payloads.

  • PDF
  • Office
  • RTF
Illustrative Document Analyzer showing suspicious document findings, active content, embedded script and executable payloads, document structure and extracted indicators.
  • Local, static analysis

    Inspect Office, PDF and RTF files without running macros or payloads.

  • Scores & detections

    Review document scores, YARA findings and ML assessments of extracted executables.

  • Structure & active content

    Unpack containers, macros, scripts and decoded layers.

  • Embedded payloads

    Extract and hash embedded objects, then open scripts or binaries in their analyzers.

  • Indicators & metadata

    Review URLs, hashes, document properties and supporting artifact detail.

Explore Document Analyzer

Examine Office documents, PDFs and RTF files for active content, external references and embedded objects. Follow suspicious components into the analyzer suited to the payload.

  • Analyze locally without executing macros or payloads. Inspect Office, PDF and RTF structure, auto-exec content and external references.
  • Review document scores, YARA findings and ATT&CK context across the file, embedded objects and decoded layers.
  • Extract and hash embedded payloads, inspect their indicators, and open scripts or executables directly in the matching analyzer.

Next pivotFrom an attachment to the script or executable hidden inside.

Inside this module
  • Office documents
  • PDF
  • RTF
  • Macros
  • External templates
  • Embedded objects
  • Extracted payloads

Your next investigation starts here

Get ThreatResponder
Forensics.

Your own investigations. Your free copy.

A standalone toolbox for examining systems, understanding artifacts and following the evidence. Request your copy and receive the download link by email.

Free for personal, non-commercial use

Use a personal email address. You don’t need a company to get started.

Using Forensics at work?

Company and commercial use requires a paid license.

Discuss company licensing

Request free copy

* Required fields

How we handle your details: Privacy notice.

We’ll email you the download link.

Open image in a new tab ↗