Tool category

Cybersecurity and DFIR

Section content

13 instruments in this category.

Threat hunting, telemetry coverage, evidence provenance, incident response and DFIR readiness.

Cybersecurity and DFIR

ATT&CK v19 Hunt Coverage Mapper

Maps hunt hypothesis, ATT&CK tactic/technique, telemetry, baseline and falsification evidence.

Best for
ATT&CK v19 hunt coverage map
Input
5 scored fields · 2 context fields
Output
ATT&CK v19 hunt coverage map
Method
crosswalk matrix
Maturity
Prototype · v1.0
Limits
Preliminary output · Human review required · Not certification
open instrument →
Cybersecurity and DFIR

Cyber Resilience Control Mapper

Maps a disruption scenario to controls, telemetry, recovery evidence and test cadence.

Best for
Cyber resilience control map
Input
6 scored fields · 1 context fields
Output
Cyber resilience control map
Method
evidence matrix
Maturity
Beta · v1.1
Limits
Preliminary output · Human review required · Not certification
open instrument →
Cybersecurity and DFIR

Cyber Telemetry Coverage Map

Maps telemetry coverage across identity, endpoint, cloud, network, email, application and data layers.

Best for
Cyber telemetry coverage map
Input
7 scored fields · 0 context fields
Output
Cyber telemetry coverage map
Method
heatmap
Maturity
Research interface · v1.9
Limits
Preliminary output · Human review required · Not certification
open instrument →
Cybersecurity and DFIR

Cyber/AI Convergence Risk Mapper

Maps where an AI system changes cyber dependencies, identities, data flows and incident-response paths.

Best for
AI-cyber dependency map
Input
5 scored fields · 1 context fields
Output
AI-cyber dependency map
Method
permission graph
Maturity
Prototype · v1.2
Limits
Preliminary output · Human review required · Not certification
open instrument →
Cybersecurity and DFIR

DFIR Evidence Map Builder

Builds an evidence source matrix and investigation sequence for a selected incident scenario.

Best for
DFIR evidence timeline and matrix
Input
5 scored fields · 0 context fields
Output
DFIR evidence timeline and matrix
Method
incident timeline
Maturity
Beta · v2.9
Limits
Preliminary output · Human review required · Not certification
open instrument →
Cybersecurity and DFIR

DFIR Evidence Provenance and Chain-of-Custody Ledger

Creates an evidence provenance and chain-of-custody checklist for incident artifacts.

Best for
DFIR evidence provenance ledger
Input
6 scored fields · 1 context fields
Output
DFIR evidence provenance ledger
Method
evidence matrix
Maturity
Prototype · v1.0
Limits
Preliminary output · Human review required · Not certification
open instrument →
Cybersecurity and DFIR

DFIR Readiness Benchmark Harness

Plans tabletop, telemetry replay, evidence acquisition and recovery benchmark tests.

Best for
DFIR readiness benchmark plan
Input
6 scored fields · 1 context fields
Output
DFIR readiness benchmark plan
Method
validation protocol
Maturity
Prototype · v1.0
Limits
Preliminary output · Human review required · Not certification
open instrument →
Cybersecurity and DFIR

DFIR Timeline Consistency Checker

Checks whether incident timestamps, evidence sources and time-zone assumptions are internally consistent.

Best for
DFIR timeline consistency note
Input
2 scored fields · 3 context fields
Output
DFIR timeline consistency note
Method
incident timeline
Maturity
Research interface · v1.3
Limits
Preliminary output · Human review required · Not certification
open instrument →
Cybersecurity and DFIR

Forensic Timeline Normalizer and Consistency Engine

Normalizes incident timestamps and flags impossible or undocumented timeline orderings.

Best for
Forensic timeline consistency report
Input
2 scored fields · 3 context fields
Output
Forensic timeline consistency report
Method
incident timeline
Maturity
Prototype · v1.0
Limits
Preliminary output · Human review required · Not certification
open instrument →
Cybersecurity and DFIR

Incident Blast Radius Estimator

Estimates likely blast-radius pressure from identity scope, lateral movement potential, data reach and dependency concentration.

Best for
Incident blast-radius review note
Input
5 scored fields · 0 context fields
Output
Incident blast-radius review note
Method
heatmap
Maturity
Research interface · v1.7
Limits
Preliminary output · Human review required · Not certification
open instrument →
Cybersecurity and DFIR

KEV Exposure Triage Tool

Prioritizes review of a known-exploited vulnerability using user-entered exposure, asset criticality and compensating controls.

Best for
Known-exploited vulnerability review note
Input
6 scored fields · 1 context fields
Output
Known-exploited vulnerability review note
Method
heatmap
Maturity
Beta · v3.1
Limits
Preliminary output · Human review required · Not certification
open instrument →
Cybersecurity and DFIR

KEV/EPSS/CVSS/NVD Prioritization Connector

Manual connector-style triage for CVE exposure using KEV, EPSS, CVSS, asset criticality and patchability evidence.

Best for
KEV/EPSS/CVSS prioritization note
Input
6 scored fields · 1 context fields
Output
KEV/EPSS/CVSS prioritization note
Method
heatmap
Maturity
Prototype · v1.0
Limits
Preliminary output · Human review required · Not certification
open instrument →
Cybersecurity and DFIR

Threat Hunting Hypothesis Builder

Turns a defensive suspicion into a hunt hypothesis with telemetry, expected observations and falsification criteria.

Best for
Threat-hunting hypothesis card
Input
4 scored fields · 1 context fields
Output
Threat-hunting hypothesis card
Method
falsification matrix
Maturity
Research interface · v1.5
Limits
Preliminary output · Human review required · Not certification
open instrument →