// artifact family
mdm / uem platform forensics
10 browser-only forensics tools in this catalog group — browse by artifact family when you know the kind of evidence you are working with, not the investigation pattern.
tools in this family
ordered as in the forensics catalog. every tool runs locally — no upload, no account.
- mobileiron uem audit log forensic analyzerdrop mobileiron audit export · parse device + policy + admin action · runs locally
- soti mobicontrol event log forensic analyzerdrop soti event export · parse device + command + compliance · runs locally
- hexnode mdm audit log forensic analyzerdrop hexnode audit export · parse device + profile + user · runs locally
- blackberry uem audit log forensic analyzerdrop blackberry uem audit export · parse device + app + compliance · runs locally
- citrix endpoint management log forensic analyzerdrop citrix endpoint mgmt export · parse device + action + policy · runs locally
- mdm device wipe anomaly detectordrop mdm command log export · detect mass remote wipe bursts · runs locally
- mdm profile tamper detectordrop mdm profile audit export · detect unauthorized profile changes · runs locally
- mdm app sideload detectordrop mdm app inventory export · detect sideloaded/unapproved apps · runs locally
- multi uem device timeline correlatordrop 2+ uem device logs · unified enrollment timeline graph · runs locally
- cross uem identity enrollment correlatordrop uem + iam exports · correlate enrolled device to owner account · runs locally