DFIRVault
Screenshot 2025-04-03 192454

Digital Forensics

Investigation Repository

A curated collection of insights, techniques, and discoveries from real-world digital forensics investigations and incident response cases.

Latest Post

  • By Jacob Wilson
  • Jan 21, 2026

VaultMirror – Robust Evidence Sync for the DFIR Professional

In the world of Digital Forensics and Incident Response, data integrity and availability are everything. Whether you are syncing evidence...

Featured Articles

Deep dives into digital forensics techniques and incident response methodologies

  • By Jacob Wilson
  • Jan 21, 2026

VaultMirror – Robust Evidence Sync for the DFIR Professional

In the world of Digital Forensics and Incident Response, data integrity and...

  • By Jacob Wilson
  • Nov 6, 2025

FivePM – Threat Hunter

It’s 4:55 PM. You’re done for the day. Then — *ping* —...

  • By Jacob Wilson
  • Sep 24, 2025

CrowdStrike Investigator

 I’ve just released a new tool: CrowdStrike AID Timeliner.This script helps investigators...

  • By Jacob Wilson
  • Aug 27, 2025

SFTP Monitor Tool

In digital forensics and incident response (DFIR), one recurring pain point I’ve...

  • By Jacob Wilson
  • Aug 20, 2025

Hayabusa Scanner Menu

Streamlining Windows Event Log Analysis with My Hayabusa Scanner Menu ToolFor many...

  • By Jacob Wilson
  • Aug 19, 2025

Dynamic Malware Analysis on an ELK Stack

Recently i begun setting up a home lab with an Elasticsearch server...

  • By Jacob Wilson
  • Aug 19, 2025

Automating Windows Event Log Analysis with Chainsaw Event Log Scanner

As a cybersecurity enthusiast, I’m always exploring ways to streamline digital forensics...

  • By Jacob Wilson
  • Aug 4, 2025

Splunk DFIR Case Manager

Why I Built This ToolAs a cybersecurity professional, I frequently work with Splunk for...

  • By Jacob Wilson
  • Aug 4, 2025

CSV Splitter

When working in digital forensics or threat intelligence, CSVs from SIEM tools,...

  • By Jacob Wilson
  • Jun 24, 2025

NGINX log parser

During DFIR investigations, especially in NGINX environments, we’re often handed a messy...

  • By Jacob Wilson
  • Jun 23, 2025

Connecting Splunk with LLM

Why Use LLMs for DFIR in Splunk?As DFIR professionals, we deal with...

  • By Jacob Wilson
  • Jun 22, 2025

DFIR THOR Drive Scanner – Fast Forensic Scans with One Click

🔍 THOR Drive Scanner – Fast Forensic Scans with One ClickNeed to...

  • By Jacob Wilson
  • Jun 21, 2025

DFIR Case Manager

📁 DFIR Case Manager – Simple Case Workflow in a ClickManaging forensic...

  • By Jacob Wilson
  • Jun 13, 2025

SpiderFoot Windows Quick Launcher

As a digital forensics and incident response (DFIR) professional, I'm always looking...

  • By Jacob Wilson
  • Jun 12, 2025

Splunk DFIR Dashboard Collection

Digital Forensics and Incident Response (DFIR) professionals know that speed and efficiency...

  • By Jacob Wilson
  • May 22, 2025

AI-Assisted Hunting: Ollama Meets ELK

When we work with a large amount of logs, sometimes millions or...

  • By Jacob Wilson
  • May 21, 2025

ForensIQ

Introducing ForensIQ: AI-Powered Elasticsearch Log Analysis for Cybersecurity Investigations The Challenge of...

  • By Jacob Wilson
  • May 21, 2025

CSV2ELK

Why I Built ThisAs a DFIR professional, I constantly deal with:CSV exports from...

  • By Jacob Wilson
  • Apr 7, 2025

Setting up logontracer daemon

Step 1 – Create Bash Script: Touch logontracer_run.sh Chmod +x logontracer_run.sh Nano...

About DFIR Vault

DFIR Vault is a personal blog dedicated to sharing insights, techniques, and discoveries from real-world digital forensics investigations and incident response engagements.

My name is Jacob Wilson, and with over a decade of experience in the cybersecurity field, I’ve encountered countless unique challenges during investigations. This repository serves as both a personal knowledge base for myself and also a resource for the wider DFIR community.

Categories

Find me using the below links:

“Digital forensics is not just about finding evidence; it’s about reconstructing the narrative of what actually happened.”