// artifact family

virtualization / hypervisor forensics

10 browser-only forensics tools in this catalog group — browse by artifact family when you know the kind of evidence you are working with, not the investigation pattern.

tools
10
catalog slugs
10
processing
local · in browser

tools in this family

ordered as in the forensics catalog. every tool runs locally — no upload, no account.

  1. vmware vcenter audit log forensic analyzerdrop vcenter audit log export · parse user + target + task name · runs locally
  2. microsoft hyper v event log forensic analyzerdrop hyper-v event log export · parse vm + host + integration service · runs locally
  3. proxmox ve task log forensic analyzerdrop proxmox task log export · parse node + vmid + task result · runs locally
  4. nutanix prism audit log forensic analyzerdrop nutanix prism audit export · parse entity + operation + cluster · runs locally
  5. ovirt engine event log forensic analyzerdrop ovirt engine event export · parse vm + host + quota · runs locally
  6. vm snapshot deletion anomaly detectordrop hypervisor snapshot audit export · detect mass snapshot purge · runs locally
  7. hypervisor console access forensic analyzerdrop vm console access log · parse user + vm + session duration · runs locally
  8. virtual machine migration timeline correlatordrop vmotion/live migration log export · unified vm move timeline · runs locally
  9. rogue vm clone detectordrop vm inventory export · detect unauthorized clones + uuid drift · runs locally
  10. multi hypervisor inventory correlatordrop 2+ hypervisor inventory exports · correlate vm uuid + name overlap · runs locally
ready