Analyst-ready reference desk

Signal in.
Clarity out.

One fast, searchable field guide for the tools and references used across triage, investigation, enrichment, and response.

Explore the library

INVESTIGATION FLOW

  1. 01Triage
  2. 02Enrich
  3. 03Investigate
  4. 04Respond
  5. 05Document

Open the right tool, faster.

Filter by investigation area, search by tool or domain, and save the references you use most.

Loading resources…

Third-party links open in a new tab

Start with the question.

Resources are most useful when they support a repeatable investigation process.

01 / PHISHING

Inspect the message and infrastructure.

  • Parse headers and authentication results
  • Enrich domains, URLs, and attachments
  • Connect delivery, click, and identity events
02 / NETWORK

Rebuild the conversation.

  • Identify source, destination, port, and protocol
  • Review packet and flow evidence
  • Compare activity against a normal baseline
03 / ENDPOINT

Follow the process tree.

  • Validate user, host, and execution context
  • Trace parent-child process relationships
  • Correlate files, persistence, and network activity
04 / RESPONSE

Turn evidence into a decision.

  • Build a timestamped evidence timeline
  • Document scope, confidence, and impact
  • Close, escalate, contain, and preserve evidence

External resources. Defensive purpose.

This guide is an index, not an endorsement. Verify each third-party service before submitting sensitive indicators, files, URLs, or organizational data. Use malware-analysis and payload resources only in isolated, authorized environments.