// artifact family
certificate / pki forensics
10 browser-only forensics tools in this catalog group — browse by artifact family when you know the kind of evidence you are working with, not the investigation pattern.
tools in this family
ordered as in the forensics catalog. every tool runs locally — no upload, no account.
- certificate transparency log forensic analyzerdrop ct log entry export · parse issuer + sans + precert/notary · runs locally
- pkcs12 keystore metadata forensic extractordrop pkcs12/pfx metadata export · parse friendly name + cert count + expiry · runs locally
- code signing certificate chain forensic analyzerdrop signed binary + cert chain export · parse publisher + timestamp + eku · runs locally
- tls client certificate handshake log forensic analyzerdrop tls client auth handshake log · parse client cert subject + verify result · runs locally
- acme certificate issuance audit forensic analyzerdrop acme server audit export · parse account + order + authorization · runs locally
- lets encrypt certbot log forensic analyzerdrop certbot/lego log export · parse domain + challenge type + renewal · runs locally
- windows certutil cert store export forensic analyzerdrop certutil -store export · parse thumbprint + template + private key hint · runs locally
- macos keychain certificate trust forensic analyzerdrop macos keychain cert export · parse trust settings + access control · runs locally
- revoked certificate ocsp crl forensic analyzerdrop ocsp/crl check log export · parse serial + revocation time + reason · runs locally
- enterprise pki template misuse detectordrop ad cs issuance log export · detect suspicious template + subject patterns · runs locally