// artifact family
drm / content protection forensics
10 browser-only forensics tools in this catalog group — browse by artifact family when you know the kind of evidence you are working with, not the investigation pattern.
tools in this family
ordered as in the forensics catalog. every tool runs locally — no upload, no account.
- widevine license request forensic analyzerdrop widevine license request/response export · parse pssh + key ids + security level · runs locally
- widevine keybox artifact forensic extractordrop android keybox/xml export · parse device id + provisioning status · runs locally
- fairplay streaming key artifact forensic analyzerdrop fairplay streaming key export · parse content key context + skd · runs locally
- playready license chain forensic analyzerdrop playready license xml/bin export · parse rights + restriction + renewal chain · runs locally
- hdcp handshake log forensic analyzerdrop hdcp auth handshake log · parse sink/source caps + link failure codes · runs locally
- eme browser media key session forensic analyzerdrop browser eme session export · parse key ids + session types + expiration · runs locally
- apple fps streaming artifact forensic extractordrop apple fps streaming cache export · parse skd + certificate chain hints · runs locally
- android mediadrm session forensic analyzerdrop android mediadrm session log · parse scheme + offline license + restore · runs locally
- chromecast widevine drm session forensic analyzerdrop cast receiver drm log export · parse stream type + hdcp level · runs locally
- drm license renewal anomaly detectordrop drm license timeline export · detect burst renewals + geo/device mismatch · runs locally