Every trace, examined.
VESTIGEX is a Windows workstation for digital forensics and incident response. Bring disk images, memory, phones and triage collections into one case, then search, hunt and report, all on your own machine.
Windows 10 / 11 · installs per user, no administrator rights
vestige (n.), a trace of something that is no longer present + examination
Timeline
1,146,208 entries · sorted by Time ↑| Time | Host | Summary |
|---|---|---|
| 02:17:44 | WKSTN-07 | 4624 Logon type 10 from 10.0.4.22 (svc_backup) |
| 02:18:09 | WKSTN-07 | 7045 Service installed: PSEXESVC HIGH |
| 02:18:11 | WKSTN-07 | Prefetch PSEXESVC.EXE, run count 1 |
| 02:19:30 | WKSTN-07 | Created C:\Windows\Temp\upd.ps1 |
| 02:19:31 | WKSTN-07 | 4104 Script block: IEX (New-Object Net.WebClient)… HIGH |
| 02:21:02 | WKSTN-07 | BAM rclone.exe last run |
| 02:24:47 | FS-02 | 5140 Share accessed: \\FS-02\Finance |
From raw evidence to a finished report, without leaving the case.
VESTIGEX indexes what you add, extracts the artifacts investigators look for, and lays it all on one timeline you can filter by host, source and date.
Evidence and file systems
Evidence- Disk images with NTFS, FAT, exFAT, ext, APFS, XFS, Btrfs and UFS
- BitLocker volumes, Volume Shadow Copies, hiberfil
- Deleted files, carving of unallocated space, NTFS MFT record carving
- Hashing with verify, hash sets, keyword search and YARA rules
Artifacts and communication
Artifacts- Registry, OS artifacts, SRUM, PowerShell 4104, per-browser web history
- Email from PST, OST, MBOX, MSG and EML
- Skype, Teams, Slack, Viber, WhatsApp Desktop and Discord
- SQLite and plist viewers, credentials page, memory with Volatility 3
Media analysis
Analysis- Photo gallery with EXIF, GPS map and offline place names
- Text in images (OCR) and speech transcription with Whisper
- Photo categories and a second opinion from the local vision model
- Video and audio players with previews carried into reports
Reporting and custody
Reporting- HTML, PDF and Excel reports with your organization's logo
- AI-drafted case summary for the examiner to edit
- Bookmarks, verdicts and notes that flow into the report
- Hash-chained custody log, audit log and examiner accounts
How a case moves through VESTIGEX
Nothing processes until you say so. Add and label your sources first, then choose what runs.
Open a case
Pick a case type and folder. One database per case keeps it portable.
Case ManagementAdd or acquire evidence
Use the wizard for images and collections, or acquire a drive or phone directly.
Data Sources › + Add / + AcquireProcess
Hashing and text extraction run in parallel. Options adapt to Windows, macOS, Linux or mobile.
Process EvidenceAnalyze and hunt
Work the timeline, artifacts and media, ask the local AI, run the threat hunt.
Timeline · FindingsReport
Export with custody records, acquisitions and bookmarked findings included.
ReportsWhat you can bring into a case
| Source | Formats and inputs | Engine |
|---|---|---|
| Disk images | E01 raw / dd VHD / VHDX and loose folders | dissect |
| Triage collections | KAPE output, Velociraptor offline collections, event logs .evtx, IIS / Apache / Nginx logs | evtx_dump, VESTIGEX parsers |
| Memory | Windows memory images and hibernation files | Volatility 3 |
| iPhone and Android | Full file system extractions, iTunes / Finder backups (encrypted too), Android logical collections | iLEAPP, ALEAPP |
| macOS | Collected files and images, with Unified Logs as an option | mac_apt |
| Linux | Images and collected files: logs, shell history, system information | dissect |
See the intrusion, host by host.
The hunt reads event logs and artifacts together. Findings group into incidents per host with recurring patterns folded, and they are marked on the timeline, the connections graph and the lateral movement view. Run it in the background and keep working.
- Findings
- A factual summary of each incident with verdicts, notes and suppressions that carry into the report.
- Lateral movement
- Logons, shares and remote services between hosts, drawn as a graph and a timeline.
- Process Inspector
- Process trees rebuilt from memory, Prefetch and BAM.
- ATT&CK & IOCs
- Technique coverage, possible threat actors, and an IOC sweep across the whole case.
- Your rules
- Write detection rules, import Sigma, and update ATT&CK, Sigma and symbol packs from Settings › Components.
- Drive or USB
- Images a whole drive or one volume to a verified E01 or raw image, hashing MD5, SHA-1 and SHA-256 as it reads. Verified against FTK Imager
- iPhone / iPad
- An encrypted backup over USB, every file hashed and checked, every change made to the device recorded. Tested on a real iPhone
- Android
- A logical collection over adb: shared storage, call log, SMS, contacts, installed apps and accounts. Tested on a real phone
- Remote hosts
- Builds a Velociraptor offline collector and imports what it brings back.
Acquire straight into the case.
Each acquisition starts by recording the authority: legal basis, reference and who authorized it. Only a verified image or backup is added as a data source, and its record goes into the report's chain of custody.
An assistant that never sends your evidence anywhere.
VESTIGEX runs language and vision models through Ollama on your own GPU. Ask questions about the case in plain language, and have it draft the case summary for you to review and edit.
Eight colour themes for long sessions, or match your Windows setting.
What happened on WKSTN-07 between 02:00 and 03:00?
A remote logon as svc_backup from 10.0.4.22 at 02:17, followed 25 seconds later by the PSEXESVC service being installed. A PowerShell script block downloaded and ran a remote script at 02:19, and rclone.exe ran at 02:21, which suggests data was copied out.
Get VESTIGEX
Install package
RecommendedWorks with Windows Smart App Control turned on. It downloads as one ZIP. Extract it to a folder and run Install VESTIGEX.cmd. The ZIP contains:
Install VESTIGEX.cmdStarts the installationvestigex.zipThe application with every tool and model. Leave it zipped; the installer unpacks itOllamaSetup.exeOptional, for the local AIVESTIGEX User Guide.pdfGetting started and every page explainedSetup wizard
AlternativeThe same installer as a classic wizard. Use it on PCs without Smart App Control until the installer is code-signed. It downloads as one ZIP; extract it and run the .exe. The ZIP contains:
VESTIGEX-Setup-1.1.1-beta.exeVESTIGEX-Setup-1.1.1-beta.binKeep next to the .exeSystem requirements
- Windows 10 or 11, 64-bit
- Windows 10 needs the Edge WebView2 runtime (built into Windows 11)
- Disk space for the 6.8 GB package, the installation and your cases
- An NVIDIA GPU is recommended for the local AI and speech transcription
Installing
- Extract the downloaded ZIP to a folder.
- Run Install VESTIGEX.cmd. No administrator rights needed.
- Open VESTIGEX from the Start menu.
- Sign in as admin / admin and choose a new password.
Good to know
- Installs for the current user in %LOCALAPPDATA%\Programs\VESTIGEX
- Upgrading keeps accounts, settings and hash sets
- Antivirus may block reading malicious evidence; exclude your case folders
- Beta software: verify important findings with a second tool
Recent releases
- Phone files are indexed like any other evidence: File System, Media Analysis, hashes, keyword search, EXIF and GPS.
- Android call log, SMS and contacts on the Messaging page; installed apps and accounts on the Mobile page.
- Threat hunt runs in the background and shows in Jobs while you keep working.
- Sortable timeline columns: under 0.2 s on 1.1 million entries.
- Acquire a drive or USB drive to a verified E01 or raw image.
- Encrypted iPhone and iPad backups over USB, without iTunes.
- Android logical collections over adb.
- Velociraptor offline collectors and import of remote collections.
- Windows desktop app with a per-user installer and everything bundled.
- In-app Help with 50 sections and a 20-page user guide.
- Threat hunt overhaul, Sigma importer and ATT&CK coverage.