Forensics

Forensics Lab

Collect forensics-grade evidence from host and service telemetry before escalation.

All parsing is local. Build command snippets, copy them safely, and classify evidence severity in-browser.

Commands

Copyable command toolkit

One-click reference

journalctl --unit=sshd --since -24h --no-pager --output=short-precise

This action should be reviewed for the target environment before execution.

Severity map

Forensics severity guide

Critical

Brute-force indicators, malware signatures, or unauthorized policy changes.

High

Credential anomalies, repeated auth failures, or suspicious command bursts.

Low

Routine maintenance churn and known benign service rotation.

Analyzer

Paste diagnostic output

Readiness checklist

Forensics findings capture

Total in this lab: 0