// artifact family

endpoint dlp forensics

10 browser-only forensics tools in this catalog group — browse by artifact family when you know the kind of evidence you are working with, not the investigation pattern.

tools
10
catalog slugs
10
processing
local · in browser

tools in this family

ordered as in the forensics catalog. every tool runs locally — no upload, no account.

  1. microsoft purview dlp incident forensic analyzerdrop purview dlp incident export · parse policy + sensitive info types + actions · runs locally
  2. forcepoint dlp incident log forensic analyzerdrop forcepoint dlp event export · parse channel + severity + destination · runs locally
  3. symantec dlp incident export forensic analyzerdrop symantec/broadcom dlp incident export · parse rule + endpoint + match count · runs locally
  4. netskope dlp alert forensic analyzerdrop netskope dlp alert export · parse app + activity + policy hit · runs locally
  5. digital guardian dlp event forensic analyzerdrop digital guardian event export · parse operation + file path + user · runs locally
  6. proofpoint dlp violation forensic analyzerdrop proofpoint dlp violation export · parse channel + dictionary + action taken · runs locally
  7. endpoint dlp usb exfil block log analyzerdrop endpoint dlp usb block log · parse device id + file hash + policy · runs locally
  8. dlp false positive pattern cluster detectordrop dlp incident corpus export · cluster repeated benign matches · runs locally
  9. dlp policy severity escalation correlatordrop dlp incident timeline export · detect severity jumps + repeat offender · runs locally
  10. multi vendor dlp incident correlatordrop 2+ dlp vendor exports · correlate user + file hash overlap · runs locally
ready