Windows text logs for forensics: Program Compatibility Assistant (execution, Windows 11), IIS and Windows Firewall (W3C), PowerShell transcripts, TeamViewer…
One multi-language AST parser: language identification from path or shebang, opt-in content parsing, tree-sitter grammar selection by cargo feature, bounded…
Browser history for forensics: visits and downloads from Chromium-family History databases (Chrome, Edge, Brave, Opera, Vivaldi), Firefox places.sqlite and…
Cloud and SaaS audit logs for forensics: AWS CloudTrail, the Microsoft 365 unified audit log, Entra ID sign-ins and audits, Azure activity, Google Cloud audit…
The Windows WMI (CIM) repository for forensics: namespaces, classes and instances read from OBJECTS.DATA, INDEX.BTR and the MAPPING files, and the event…
The FusionVault Streams engine: runs a stream pipeline continuously over Kafka with N independent consumer threads, stateful operators from fv-streams-ops,…
Windows Server User Access Logging (UAL, the Sum folder's .mdb databases) for forensics: which accounts and addresses used which server role, when, and how…
Credential verification and query scope derivation, shared by the control plane's forensics authorization funnel and the standalone Query plane, with no…
Microsoft Defender for forensics: its detection history files (what was detected, where, when, by which process, for which user, and the file's SHA-256) and…
Opt-in Kafka building blocks for Mercury: publish events to topics (simple.kafka.notification) and route topics into Event Script flows, with externalized…
Cranpose's patched fork of wgpu-hal 30.0.1 (forks/README.md in the Cranpose repository). Hardware abstraction layer for wgpu, the cross-platform, safe,…
Windows scheduled tasks for forensics: the task XML files of System32\Tasks and the .job files of older Windows (what runs, as whom, when, hidden or not).
Cranpose's patched fork of wgpu-core 30.0.1 (forks/README.md in the Cranpose repository). Core implementation logic of wgpu, the cross-platform, safe,…
Web server access logs for forensics: Apache and nginx (common, combined, virtual host), Jira, Confluence and Bitbucket, AWS load balancers (ELB) and Azure…