// artifact family

network detection & response forensics

10 browser-only forensics tools in this catalog group — browse by artifact family when you know the kind of evidence you are working with, not the investigation pattern.

tools
10
catalog slugs
10
processing
local · in browser

tools in this family

ordered as in the forensics catalog. every tool runs locally — no upload, no account.

  1. darktrace model breach export forensic analyzerdrop darktrace breach export · parse model + device + score · runs locally
  2. vectra ai detect export forensic analyzerdrop vectra detect export · parse host + detection + certainty · runs locally
  3. extrahop revealx export forensic analyzerdrop extrahop revealx export · parse device + protocol + risk · runs locally
  4. corelight network security export forensic analyzerdrop corelight export · parse conn + dns + http meta · runs locally
  5. gigamon metadata export forensic analyzerdrop gigamon metadata export · parse flow + app + tunnel · runs locally
  6. ndr east west traffic anomaly detectordrop ndr flow export · detect east-west traffic anomalies · runs locally
  7. ndr c2 beaconing pattern detectordrop ndr session export · detect c2 beaconing intervals · runs locally
  8. ndr data exfiltration volume detectordrop ndr flow export · detect outbound data exfil bursts · runs locally
  9. multi ndr threat timeline correlatordrop 2+ ndr exports · unified network threat timeline graph · runs locally
  10. cross ndr edr incident correlatordrop ndr + edr exports · correlate network alert to host incident · runs locally
ready