Tool category
Cybersecurity and DFIR
Section content
13 instruments in this category.
Threat hunting, telemetry coverage, evidence provenance, incident response and DFIR readiness.
ATT&CK v19 Hunt Coverage Mapper
Maps hunt hypothesis, ATT&CK tactic/technique, telemetry, baseline and falsification evidence.
- Best for
- ATT&CK v19 hunt coverage map
- Input
- 5 scored fields · 2 context fields
- Output
- ATT&CK v19 hunt coverage map
- Method
- crosswalk matrix
- Maturity
- Prototype · v1.0
- Limits
- Preliminary output · Human review required · Not certification
Cyber Resilience Control Mapper
Maps a disruption scenario to controls, telemetry, recovery evidence and test cadence.
- Best for
- Cyber resilience control map
- Input
- 6 scored fields · 1 context fields
- Output
- Cyber resilience control map
- Method
- evidence matrix
- Maturity
- Beta · v1.1
- Limits
- Preliminary output · Human review required · Not certification
Cyber Telemetry Coverage Map
Maps telemetry coverage across identity, endpoint, cloud, network, email, application and data layers.
- Best for
- Cyber telemetry coverage map
- Input
- 7 scored fields · 0 context fields
- Output
- Cyber telemetry coverage map
- Method
- heatmap
- Maturity
- Research interface · v1.9
- Limits
- Preliminary output · Human review required · Not certification
Cyber/AI Convergence Risk Mapper
Maps where an AI system changes cyber dependencies, identities, data flows and incident-response paths.
- Best for
- AI-cyber dependency map
- Input
- 5 scored fields · 1 context fields
- Output
- AI-cyber dependency map
- Method
- permission graph
- Maturity
- Prototype · v1.2
- Limits
- Preliminary output · Human review required · Not certification
DFIR Evidence Map Builder
Builds an evidence source matrix and investigation sequence for a selected incident scenario.
- Best for
- DFIR evidence timeline and matrix
- Input
- 5 scored fields · 0 context fields
- Output
- DFIR evidence timeline and matrix
- Method
- incident timeline
- Maturity
- Beta · v2.9
- Limits
- Preliminary output · Human review required · Not certification
DFIR Evidence Provenance and Chain-of-Custody Ledger
Creates an evidence provenance and chain-of-custody checklist for incident artifacts.
- Best for
- DFIR evidence provenance ledger
- Input
- 6 scored fields · 1 context fields
- Output
- DFIR evidence provenance ledger
- Method
- evidence matrix
- Maturity
- Prototype · v1.0
- Limits
- Preliminary output · Human review required · Not certification
DFIR Readiness Benchmark Harness
Plans tabletop, telemetry replay, evidence acquisition and recovery benchmark tests.
- Best for
- DFIR readiness benchmark plan
- Input
- 6 scored fields · 1 context fields
- Output
- DFIR readiness benchmark plan
- Method
- validation protocol
- Maturity
- Prototype · v1.0
- Limits
- Preliminary output · Human review required · Not certification
DFIR Timeline Consistency Checker
Checks whether incident timestamps, evidence sources and time-zone assumptions are internally consistent.
- Best for
- DFIR timeline consistency note
- Input
- 2 scored fields · 3 context fields
- Output
- DFIR timeline consistency note
- Method
- incident timeline
- Maturity
- Research interface · v1.3
- Limits
- Preliminary output · Human review required · Not certification
Forensic Timeline Normalizer and Consistency Engine
Normalizes incident timestamps and flags impossible or undocumented timeline orderings.
- Best for
- Forensic timeline consistency report
- Input
- 2 scored fields · 3 context fields
- Output
- Forensic timeline consistency report
- Method
- incident timeline
- Maturity
- Prototype · v1.0
- Limits
- Preliminary output · Human review required · Not certification
Incident Blast Radius Estimator
Estimates likely blast-radius pressure from identity scope, lateral movement potential, data reach and dependency concentration.
- Best for
- Incident blast-radius review note
- Input
- 5 scored fields · 0 context fields
- Output
- Incident blast-radius review note
- Method
- heatmap
- Maturity
- Research interface · v1.7
- Limits
- Preliminary output · Human review required · Not certification
KEV Exposure Triage Tool
Prioritizes review of a known-exploited vulnerability using user-entered exposure, asset criticality and compensating controls.
- Best for
- Known-exploited vulnerability review note
- Input
- 6 scored fields · 1 context fields
- Output
- Known-exploited vulnerability review note
- Method
- heatmap
- Maturity
- Beta · v3.1
- Limits
- Preliminary output · Human review required · Not certification
KEV/EPSS/CVSS/NVD Prioritization Connector
Manual connector-style triage for CVE exposure using KEV, EPSS, CVSS, asset criticality and patchability evidence.
- Best for
- KEV/EPSS/CVSS prioritization note
- Input
- 6 scored fields · 1 context fields
- Output
- KEV/EPSS/CVSS prioritization note
- Method
- heatmap
- Maturity
- Prototype · v1.0
- Limits
- Preliminary output · Human review required · Not certification
Threat Hunting Hypothesis Builder
Turns a defensive suspicion into a hunt hypothesis with telemetry, expected observations and falsification criteria.
- Best for
- Threat-hunting hypothesis card
- Input
- 4 scored fields · 1 context fields
- Output
- Threat-hunting hypothesis card
- Method
- falsification matrix
- Maturity
- Research interface · v1.5
- Limits
- Preliminary output · Human review required · Not certification