Self-contained, offline-capable DFIR reference pages for Windows artifact analysis. Download any tool as a single HTML file and use it anywhere.
Comprehensive registry artifact reference covering persistence, execution, user activity, credential access, and network configuration. Includes 23 LOLRMM-abused RMM tools, 70 ATT&CK techniques, and notable attacker tools with forensic guidance.
Complete Security.evtx event ID reference with Microsoft Appendix L criticality tiers (High/Medium/Low), investigation notes for key events, and 60 curated Sigma detection rules with full-database search across 195 rules.
Complete Sysmon v15.2 reference covering all 30 event IDs with key fields, noise level ratings, configuration guidance, and 80 curated Sigma detection rules. Full-database search across 195 Sysmon-specific detection rules via companion JSON.
Focused, cross-channel references for activity types that span multiple log sources — faster to scan than the full explorers above. Browse all references →
Security, TerminalServices-RemoteConnectionManager, LocalSessionManager, and RDPCoreTS. Brute force, session hijacking, mass lateral movement.
Security rule-change events, WFP connection/bind events, and the dedicated Firewall operational channel.
Share access events plus SMBClient operational log. Lateral movement, NTDS.dit exfiltration, IPC$ enumeration.
Security audit events plus the always-on TaskScheduler/Operational log. Task hijacking and persistence detection.
Bits-Client/Operational log. Stealthy downloads, exfiltration, and SetNotifyCmdLine persistence.
Defender operational log plus Security Center corroboration. Detection events, AV-disable evasion, Tamper Protection.
Script block/module logging, legacy log, and the separate PowerShell 7 (Core) channel. AMSI bypass, credential access, download cradles.
Native WMI-Activity/Operational log, available on every host by default. Permanent event consumers, remote execution, polling beacons.
A set of self-contained HTML reference pages for Windows digital forensics and incident response. Each tool covers a specific evidence source — registry hives, Security event log, and Sysmon — with artifact documentation, forensic investigation notes, and detection rules.
Built for practitioners who need fast, offline-capable references during investigations. No login, no tracking, no dependencies beyond Google Fonts.
Each tool includes a curated set of SigmaHQ detection rules hand-selected for investigative relevance. Rules are vendor-agnostic YAML — convert to Splunk, Elastic, Microsoft Sentinel, QRadar, and others via sigconverter.io.
The Sysmon tool includes a full 195-rule companion JSON database with keyword search, surfacing rules beyond the curated set.
Registry artifacts are mapped to MITRE ATT&CK Enterprise techniques — 251 total artifacts have direct technique mappings. Filter by tactic (Persistence, Credential Access, Defense Evasion, etc.) to focus investigation on relevant keys.
Security Event IDs and Sigma rules are also tagged with ATT&CK technique IDs linking directly to attack.mitre.org.
Each tool works fully offline — download the HTML file and open it in any browser. Filters, search, expand/collapse, copy buttons, and all cross-references work without an internet connection (Google Fonts degrades gracefully to system fonts).
The Registry and Sysmon tools are backed by versioned JSON schema files designed to be updated independently of the HTML as new artifacts, techniques, and detection rules become available:
windows_registry_artifacts_schema_v0.3.json
sysmon_rules_complete.json
linux_artifacts_schema_v0.1.json
Security Event IDs are well-documented in Microsoft Appendix L — no separate schema file is maintained for that reference.