// artifact family

certificate / pki forensics

10 browser-only forensics tools in this catalog group — browse by artifact family when you know the kind of evidence you are working with, not the investigation pattern.

tools
10
catalog slugs
10
processing
local · in browser

tools in this family

ordered as in the forensics catalog. every tool runs locally — no upload, no account.

  1. certificate transparency log forensic analyzerdrop ct log entry export · parse issuer + sans + precert/notary · runs locally
  2. pkcs12 keystore metadata forensic extractordrop pkcs12/pfx metadata export · parse friendly name + cert count + expiry · runs locally
  3. code signing certificate chain forensic analyzerdrop signed binary + cert chain export · parse publisher + timestamp + eku · runs locally
  4. tls client certificate handshake log forensic analyzerdrop tls client auth handshake log · parse client cert subject + verify result · runs locally
  5. acme certificate issuance audit forensic analyzerdrop acme server audit export · parse account + order + authorization · runs locally
  6. lets encrypt certbot log forensic analyzerdrop certbot/lego log export · parse domain + challenge type + renewal · runs locally
  7. windows certutil cert store export forensic analyzerdrop certutil -store export · parse thumbprint + template + private key hint · runs locally
  8. macos keychain certificate trust forensic analyzerdrop macos keychain cert export · parse trust settings + access control · runs locally
  9. revoked certificate ocsp crl forensic analyzerdrop ocsp/crl check log export · parse serial + revocation time + reason · runs locally
  10. enterprise pki template misuse detectordrop ad cs issuance log export · detect suspicious template + subject patterns · runs locally
ready