DFIR platform
Forensis
Investigation tooling that brings evidence, triage, and response into one workspace.
- Focus
- DFIR platform
- Updated
- May 2026
- Stack
- Python, Flask, YARA, Sigma, Docker
Overview
Built for operational clarity.
A threat analysis and digital forensics platform covering logs, network evidence, memory triage, playbooks, Sigma correlation, and secured administration.
This project reflects a product-oriented approach to security engineering: start with a recurring operational problem, reduce unnecessary steps, and make the result usable across real environments.
What it delivers
01Log and PCAP analysis
02Memory triage
03Sigma correlation
04MFA administration
Engineering approach
Portable, inspectable, and ready to operate.
The implementation emphasizes explicit workflows, deployable packaging, and technology choices that remain understandable to the teams running them.
PythonFlaskYARASigmaDocker