// artifact family
email archiving / journaling forensics
10 browser-only forensics tools in this catalog group — browse by artifact family when you know the kind of evidence you are working with, not the investigation pattern.
tools in this family
ordered as in the forensics catalog. every tool runs locally — no upload, no account.
- veritas enterprise vault journal export forensic analyzerdrop enterprise vault journal export · parse archive id + envelope + retention class · runs locally
- mimecast email archive export forensic analyzerdrop mimecast archive search export · parse message id + route + retention · runs locally
- proofpoint archiving compliance export forensic analyzerdrop proofpoint archive export · parse policy + disposition + legal hold · runs locally
- microsoft purview exchange journal export analyzerdrop exchange journal mailbox export · parse envelope + recipient + transport · runs locally
- barracuda message archiver export forensic analyzerdrop barracuda archiver export · parse message store + index + hash · runs locally
- google vault matter export forensic analyzerdrop google vault matter export · parse account + query scope + export batch · runs locally
- smarsh archiving export forensic analyzerdrop smarsh connected archive export · parse channel + participant + policy tag · runs locally
- email journal deletion anomaly detectordrop archive audit log export · detect purge bursts + hold bypass · runs locally
- legal hold overlap correlatordrop 2+ legal hold exports · correlate custodian + matter overlap · runs locally
- multi archive mailbox timeline correlatordrop 2+ archive exports · unified message timeline graph · runs locally