// artifact family
linux systemd native
17 browser-only forensics tools in this catalog group — browse by artifact family when you know the kind of evidence you are working with, not the investigation pattern.
tools in this family
ordered as in the forensics catalog. every tool runs locally — no upload, no account.
- apparmor profile change forensic analyzerdrop apparmor profile dir + audit · parse profile transitions · runs locally
- dbus session log forensic analyzerdrop dbus daemon log · parse method calls + signals + service ownership · runs locally
- flatpak installation artifact forensic extractordrop /var/lib/flatpak + ~/.local/share/flatpak · parse installed apps + remotes · runs locally
- gnome recent files forensic extractordrop ~/.local/share/recently-used.xbel · parse recent files + apps · runs locally
- selinux audit log forensic analyzerdrop /var/log/audit/audit.log · parse avc + syscall messages · runs locally
- selinux policy diff forensic analyzerdrop two selinux policy dumps · diff booleans + modules + contexts · runs locally
- snap package artifact forensic extractordrop /var/lib/snapd · parse installed snaps + revisions + interfaces · runs locally
- systemd journal binary forensic analyzerdrop systemd journal .journal · parse messages + cursors + units · runs locally
- systemd timer persistence abuse detectordrop systemd timer + service inventory · detect timer-as-persistence patterns · runs locally
- systemd unit and timer forensic analyzerdrop /etc/systemd + /lib/systemd dump · parse units + timers + drop-ins + dependencies · runs locally
- appimage execution trace forensic analyzerdrop ~/.cache + ~/.local + journal · trace appimage execution events · runs locally
- firewalld direct rule modification detectordrop firewalld log + config · detect direct rule abuse · runs locally
- gnome tracker database forensic extractordrop gnome tracker db · parse indexed files + metadata · runs locally
- kde baloo index forensic extractordrop kde baloo index · parse indexed files + metadata · runs locally
- nftables rule change forensic analyzerdrop nftables ruleset dump + journal · parse rule diff · runs locally
- systemd resolved dns cache forensic extractordrop systemd-resolved cache · parse cached records · runs locally
- ufw rule change forensic analyzerdrop ufw log · parse rule changes + deny/allow stats · runs locally