// artifact family

email security gateway forensics

10 browser-only forensics tools in this catalog group — browse by artifact family when you know the kind of evidence you are working with, not the investigation pattern.

tools
10
catalog slugs
10
processing
local · in browser

tools in this family

ordered as in the forensics catalog. every tool runs locally — no upload, no account.

  1. proofpoint tap alert export forensic analyzerdrop proofpoint tap alert export · parse threat id + sender + url rewrite · runs locally
  2. mimecast message tracking log forensic analyzerdrop mimecast tracking export · parse delivery route + held/rejected + impersonation · runs locally
  3. barracuda email security log forensic analyzerdrop barracuda ess log export · parse spam/virus/phish scores + actions · runs locally
  4. microsoft defender office365 message trace forensic analyzerdrop m365 message trace export · parse delivery status + threat detections · runs locally
  5. cisco email security appliance log forensic analyzerdrop cisco esa mail log export · parse dlp + outbreak + quarantine events · runs locally
  6. forcepoint email security gateway log forensic analyzerdrop forcepoint esg log export · parse policy hits + sandbox verdict · runs locally
  7. email url rewrite chain forensic analyzerdrop secure link rewrite export · parse original vs wrapped url chains · runs locally
  8. phishing kit landing page artifact forensic extractordrop captured phish kit html/js export · parse form targets + exfil endpoints · runs locally
  9. bec impersonation thread forensic analyzerdrop gateway + mailbox exports · detect display-name spoof + reply-to drift · runs locally
  10. email security gateway quarantine release forensic analyzerdrop quarantine release audit export · parse reviewer + release reason timeline · runs locally
ready