// artifact family
msp / rmm platform forensics
10 browser-only forensics tools in this catalog group — browse by artifact family when you know the kind of evidence you are working with, not the investigation pattern.
tools in this family
ordered as in the forensics catalog. every tool runs locally — no upload, no account.
- connectwise automate audit log forensic analyzerdrop connectwise automate export · parse computer + script + result · runs locally
- datto rmm script execution forensic analyzerdrop datto rmm script log export · parse device + script + exit code · runs locally
- ninjaone device management audit forensic analyzerdrop ninjaone audit export · parse device + action + technician · runs locally
- kaseya vsa agent execution forensic analyzerdrop kaseya vsa export · parse agent + procedure + status · runs locally
- n-able n-central audit log forensic analyzerdrop n-able n-central export · parse device + job + operator · runs locally
- syncro msp ticket audit forensic analyzerdrop syncro msp export · parse ticket + remote session + technician · runs locally
- rmm remote shell anomaly detectordrop rmm remote session export · detect off-hours shell bursts · runs locally
- rmm mass script deployment detectordrop rmm script deployment export · detect mass endpoint script pushes · runs locally
- multi rmm endpoint timeline correlatordrop 2+ rmm exports · unified endpoint action timeline graph · runs locally
- cross rmm edr incident correlatordrop rmm + edr exports · correlate remote action to host alert · runs locally