VESTIGEX Digital Forensics & Investigation Platform VESTIGEX Digital Forensics & Investigation Platform
Digital forensics & investigation platform

Every trace, examined.

VESTIGEX is a Windows workstation for digital forensics and incident response. Bring disk images, memory, phones and triage collections into one case, then search, hunt and report, all on your own machine.

Windows 10 / 11 · installs per user, no administrator rights

vestige (n.), a trace of something that is no longer present  +  examination

Illustration with sample data
Offline by designEvidence and AI stay on the examiner's PC.
One case, every sourceDisk, memory, phone, macOS, Linux, logs.
Chain of custody built inHash-chained custody log and audit trail.
Everything bundledPython, models and tools ship in the installer.
Capabilities

From raw evidence to a finished report, without leaving the case.

VESTIGEX indexes what you add, extracts the artifacts investigators look for, and lays it all on one timeline you can filter by host, source and date.

Evidence and file systems

Evidence
  • Disk images with NTFS, FAT, exFAT, ext, APFS, XFS, Btrfs and UFS
  • BitLocker volumes, Volume Shadow Copies, hiberfil
  • Deleted files, carving of unallocated space, NTFS MFT record carving
  • Hashing with verify, hash sets, keyword search and YARA rules

Artifacts and communication

Artifacts
  • Registry, OS artifacts, SRUM, PowerShell 4104, per-browser web history
  • Email from PST, OST, MBOX, MSG and EML
  • Skype, Teams, Slack, Viber, WhatsApp Desktop and Discord
  • SQLite and plist viewers, credentials page, memory with Volatility 3

Media analysis

Analysis
  • Photo gallery with EXIF, GPS map and offline place names
  • Text in images (OCR) and speech transcription with Whisper
  • Photo categories and a second opinion from the local vision model
  • Video and audio players with previews carried into reports

Reporting and custody

Reporting
  • HTML, PDF and Excel reports with your organization's logo
  • AI-drafted case summary for the examiner to edit
  • Bookmarks, verdicts and notes that flow into the report
  • Hash-chained custody log, audit log and examiner accounts
Workflow

How a case moves through VESTIGEX

Nothing processes until you say so. Add and label your sources first, then choose what runs.

Open a case

Pick a case type and folder. One database per case keeps it portable.

Case Management

Add or acquire evidence

Use the wizard for images and collections, or acquire a drive or phone directly.

Data Sources › + Add / + Acquire

Process

Hashing and text extraction run in parallel. Options adapt to Windows, macOS, Linux or mobile.

Process Evidence

Analyze and hunt

Work the timeline, artifacts and media, ask the local AI, run the threat hunt.

Timeline · Findings

Report

Export with custody records, acquisitions and bookmarked findings included.

Reports
Supported evidence

What you can bring into a case

SourceFormats and inputsEngine
Disk imagesE01 raw / dd VHD / VHDX and loose foldersdissect
Triage collectionsKAPE output, Velociraptor offline collections, event logs .evtx, IIS / Apache / Nginx logsevtx_dump, VESTIGEX parsers
MemoryWindows memory images and hibernation filesVolatility 3
iPhone and AndroidFull file system extractions, iTunes / Finder backups (encrypted too), Android logical collectionsiLEAPP, ALEAPP
macOSCollected files and images, with Unified Logs as an optionmac_apt
LinuxImages and collected files: logs, shell history, system informationdissect
Threat hunt

See the intrusion, host by host.

The hunt reads event logs and artifacts together. Findings group into incidents per host with recurring patterns folded, and they are marked on the timeline, the connections graph and the lateral movement view. Run it in the background and keep working.

2,431Sigma rules imported (SigmaHQ)
176threat groups in ATT&CK v19.2
18artifact-based hunt rules
Findings
A factual summary of each incident with verdicts, notes and suppressions that carry into the report.
Lateral movement
Logons, shares and remote services between hosts, drawn as a graph and a timeline.
Process Inspector
Process trees rebuilt from memory, Prefetch and BAM.
ATT&CK & IOCs
Technique coverage, possible threat actors, and an IOC sweep across the whole case.
Your rules
Write detection rules, import Sigma, and update ATT&CK, Sigma and symbol packs from Settings › Components.
Drive or USB
Images a whole drive or one volume to a verified E01 or raw image, hashing MD5, SHA-1 and SHA-256 as it reads. Verified against FTK Imager
iPhone / iPad
An encrypted backup over USB, every file hashed and checked, every change made to the device recorded. Tested on a real iPhone
Android
A logical collection over adb: shared storage, call log, SMS, contacts, installed apps and accounts. Tested on a real phone
Remote hosts
Builds a Velociraptor offline collector and imports what it brings back.
Acquisition

Acquire straight into the case.

Each acquisition starts by recording the authority: legal basis, reference and who authorized it. Only a verified image or backup is added as a data source, and its record goes into the report's chain of custody.

Local AI

An assistant that never sends your evidence anywhere.

VESTIGEX runs language and vision models through Ollama on your own GPU. Ask questions about the case in plain language, and have it draft the case summary for you to review and edit.

Graphite Dim Blue Green Dark Coffee Light Pink Coffee

Eight colour themes for long sessions, or match your Windows setting.

Download

Get VESTIGEX

1.1.1-betaPhones and fixes · Windows 10 and 11, 64-bit

Install package

Recommended

Works with Windows Smart App Control turned on. It downloads as one ZIP. Extract it to a folder and run Install VESTIGEX.cmd. The ZIP contains:

Install VESTIGEX.cmdStarts the installation
script
vestigex.zipThe application with every tool and model. Leave it zipped; the installer unpacks it
6.8 GB
OllamaSetup.exeOptional, for the local AI
installer
VESTIGEX User Guide.pdfGetting started and every page explained
PDF
Download install package Hosted on Google Drive. Large files open a "can't scan for viruses" notice; choose Download anyway.

Setup wizard

Alternative

The same installer as a classic wizard. Use it on PCs without Smart App Control until the installer is code-signed. It downloads as one ZIP; extract it and run the .exe. The ZIP contains:

VESTIGEX-Setup-1.1.1-beta.exe
wizard
VESTIGEX-Setup-1.1.1-beta.binKeep next to the .exe
data
Download setup wizard Read the user guide (PDF)

System requirements

  • Windows 10 or 11, 64-bit
  • Windows 10 needs the Edge WebView2 runtime (built into Windows 11)
  • Disk space for the 6.8 GB package, the installation and your cases
  • An NVIDIA GPU is recommended for the local AI and speech transcription

Installing

  1. Extract the downloaded ZIP to a folder.
  2. Run Install VESTIGEX.cmd. No administrator rights needed.
  3. Open VESTIGEX from the Start menu.
  4. Sign in as admin / admin and choose a new password.

Good to know

  • Installs for the current user in %LOCALAPPDATA%\Programs\VESTIGEX
  • Upgrading keeps accounts, settings and hash sets
  • Antivirus may block reading malicious evidence; exclude your case folders
  • Beta software: verify important findings with a second tool
Changelog

Recent releases

1.1.1-beta
Phones and fixes
  • Phone files are indexed like any other evidence: File System, Media Analysis, hashes, keyword search, EXIF and GPS.
  • Android call log, SMS and contacts on the Messaging page; installed apps and accounts on the Mobile page.
  • Threat hunt runs in the background and shows in Jobs while you keep working.
  • Sortable timeline columns: under 0.2 s on 1.1 million entries.
1.1.0-beta
Acquisition
  • Acquire a drive or USB drive to a verified E01 or raw image.
  • Encrypted iPhone and iPad backups over USB, without iTunes.
  • Android logical collections over adb.
  • Velociraptor offline collectors and import of remote collections.
1.0.0-beta
First release
  • Windows desktop app with a per-user installer and everything bundled.
  • In-app Help with 50 sections and a 20-page user guide.
  • Threat hunt overhaul, Sigma importer and ATT&CK coverage.