Digital Forensics and Incident Response Platform

Forensica

One evidence body, one query language, one integrity chain, one interface language. Engines plug in and out; the evidence body remains.

Fully offlineOCSF-nativeFour-step chain of custodyAir-gapped deployment

Why it exists

DFIR teams today use nine separate tools on average.

A case manager, a timeline, a memory analyser, a disk analyser, a log hunter, a live collector, a threat intelligence store, a sandbox, a reporting tool. Each arrives with its own authentication, its own data model, its own chain of custody and its own interface language.

That has a measurable cost: moving a finding between tools takes 4–11 minutes on average; with nine separate hash ledgers there is no single answer in court to “where did this line come from”; and disk artefact, network flow and cloud audit record never enter the same query.

  • Case & CustodyCase, chain of custody, legal hold
  • AcquireLive triage, disk image, memory, cloud
  • IngestParser pipeline, OCSF mapping, timestamping
  • AnalyzeDisk, memory, network, Windows artefacts, mobile
  • DetectFQL, Sigma compiler, YARA, ATT&CK mapping
  • TimelineSuper timeline, gap detection
  • GraphEntity graph, lateral movement, attack path
  • CopilotLocal LLM, evidence RAG, report draft
  • ReportLegal templates, evidence package, verification script
  • RespondIsolation, IOC blocking, four-eyes approval
  • IntelThreat intelligence and IOC lifecycle

Forensica is under development; contact us about pilot studies and early access.

Three outputs

From forecast to action.

EVIDENCE DNA

Evidence DNA

Record hash → Merkle path → chain → RFC 3161 timestamp. All four steps are reported separately; partial verification never looks like “verified”.

FQL

One query language

The same query runs over historical data, on the live endpoint and in vector search. Sigma rules compile to SQL.

OFFLINE AI

Offline artificial intelligence

Model weights ship inside the image and run in an air-gapped environment. Every answer cites its source record, or it is not shown.

Five decisions that carry the differentiation

What it does

OCSF-native evidence lake

Every artefact, whatever its source, is normalised to an open standard. No data lock-in; it flows straight into a SIEM.

Four-step integrity chain

Competitors show a single tick and partial verification looks complete. Here each step is reported separately.

FQL and a Sigma compiler

One query language; columnar scanning makes it many times faster than classic tooling, without licence entanglement.

Fully offline AI

Most forensic units cannot send data to the cloud. The model runs inside the image and every answer carries a source record.

Evidence Console design language

An interface designed for a screen that will go to court: density-first, and it never hides uncertainty.

A

An honest note on scope

  • Forensica performs analysis on mobile devices; it does not perform physical extraction.
  • Output from extraction tools such as UFED or GrayKey is imported and merged into the same evidence body.
  • Mobile extraction tools are positioned as complementary, not competing.
  • A raw evidence file can never be modified, deleted or renamed on any code path.
  • Every derived record must be traceable back to its root.
B

Deployment

  • On-premise, air-gapped or Kubernetes deployment
  • Collection agent shipped as a single static binary (Windows / Linux / macOS)
  • Export via OCSF and Parquet — data portability guaranteed
  • Turkish and English interface, legal report templates in both languages
  • Role-based authorisation and four-eyes approval gates

Module map

  • Case & Custody
    Case, chain of custody, legal hold
  • Acquire
    Live triage, disk image, memory, cloud
  • Ingest
    Parser pipeline, OCSF mapping, timestamping
  • Analyze
    Disk, memory, network, Windows artefacts, mobile
  • Detect
    FQL, Sigma compiler, YARA, ATT&CK mapping
  • Timeline
    Super timeline, gap detection

Request a demo

We can run a short evaluation in your own environment.

Request a demo

Get started

Let us talk about your project.

The first meeting is a discovery session, not a sales pitch. You are also welcome to evaluate our capability directly through a short pilot or proof of concept (PoC) in your own environment.

Fill in the enquiry form

WhatsApp