Find forensic artifacts, fast

Search artifact paths, build collection scripts, and convert Sigma rules. All in one place.

search "|"
/
Investigate by scenario

// WHY DFIRHUB

Always Current

Artifacts synced weekly from KapeFiles. Always up to date with the latest forensic targets.

Browser-Native

Everything runs in your browser. No server, no telemetry, no data leaves your machine.

Investigation-Ready

From artifact lookup to collection script in seconds. Built for DFIR practitioners.

// POPULAR ARTIFACTS

view all →