// artifact family

ics vendor / hmi platform forensics

10 browser-only forensics tools in this catalog group — browse by artifact family when you know the kind of evidence you are working with, not the investigation pattern.

tools
10
catalog slugs
10
processing
local · in browser

tools in this family

ordered as in the forensics catalog. every tool runs locally — no upload, no account.

  1. inductive automation ignition audit log forensic analyzerdrop ignition audit export · parse tag + project + user action · runs locally
  2. siemens wincc audit log forensic analyzerdrop wincc audit export · parse screen + tag + operator · runs locally
  3. rockwell factorytalk audit log forensic analyzerdrop factorytalk audit export · parse controller + tag + change · runs locally
  4. ge ifix audit log forensic analyzerdrop ifix audit export · parse alarm + tag + operator · runs locally
  5. vtscada event log forensic analyzerdrop vtscada event export · parse alarm + device + ack · runs locally
  6. hmi tag database change detectordrop hmi tag db export · detect unauthorized tag modifications · runs locally
  7. plc program upload anomaly detectordrop plc upload log export · detect off-hours program uploads · runs locally
  8. scada operator command anomaly detectordrop scada command log export · detect dangerous operator commands · runs locally
  9. multi hmi alarm timeline correlatordrop 2+ hmi alarm exports · unified scada alarm timeline graph · runs locally
  10. cross ics hmi network correlatordrop hmi + network flow exports · correlate tag change to ip/session · runs locally
ready