computer

Digivetus Factium

computer

Digivetus Factium

Digivetus Factium is an all-in-one computer forensic analysis platform for law enforcement, legal and forensic labs, enterprise investigations, incident response, and authorized private research.

Gallery

Digivetus Factium— Digital Forensics Workbench

Every byte tells a story — Digivetus Factium listens



Digivetus Factium is an all-in-one **computer forensic analysis platform for law enforcement, legal and forensic labs, enterprise investigations, incident response, and authorized private research. Built on a deeply customized sleuth kit core, it takes you from disk image ingestion through file-system exploration, artifact parsing, timeline review, AI-assisted triage, and court-ready reporting—on a single workstation, with no cloud dependency.


## Who it is for

| Audience | Typical use |
|----------|-------------|
| Law enforcement & cybercrime units | Electronic evidence examination, case building, disclosure |
| Forensic laboratories | Independent validation and expert reports |
| Corporate security & HR/legal | Insider cases, IP theft, data exfiltration |
| Incident response | Ransomware, intrusion, rapid scoping on acquired images |
| Education & research | Transparent, auditable forensic toolchain |

## End-to-end investigation flow

1. **Open or create a case** — structured case metadata and evidence list
2. **Load disk images** — E01, DD, RAW, VHD/VHDX, VMDK, QCOW, and more
3. **Browse evidence** — partitions, directories, deleted content, hex/text preview
4. **Run the forensic pipeline** — modular scan catalog (hundreds of parsers), keyword search, optional timeline correlation
5. **Review results** — AXIOM-style forensic module tree, search hits, email/IM panels, unified timeline view
6. **Persist to the case database** — SQLite `case.db` for reopen, filter by scan session, export on demand
7. **Report & testify** — HTML, PDF, CSV, bookmarks, audit trail, image hashes

## Core capabilities

| Capability | What you get |
|------------|--------------|
| **Forensic-grade engine** | Source-level integration of libtsk, libewf, libvhdi, libvmdk, libqcow, libpff—not a thin wrapper |
| **Large parser catalog** | **480+** selectable scan modules across Windows, macOS, and Linux artifacts |
| **Unified case database** | Magnet AXIOM–style logical model: artifacts, attributes, timeline events, keywords, sessions |
| **Timeline analysis** | Events from parsers aggregated into `dh_timeline_events`; dedicated Timeline View with lazy loading |
| **Keyword & content search** | Hit review panel, optional full-text indexing from hits |
| **Email & IM forensics** | PST/OST-style mail workflows; IM app extraction (Telegram, Discord, Signal, Skype, Teams, etc.) |
| **Credentials & secrets** | Browser stores, Wi‑Fi, SSH, DPAPI-related material, KeePass, wallets (breadth varies by module) |
| **Threat & anti-forensics** | Defender logs, persistence (WMI, COM, tasks), log-clearing indicators, known wiper tools |
| **Carving & compound files** | Recovered files metadata; archive expansion where supported |
| **Local AI assistant** | Offline `.gguf` models via llama.cpp; natural-language driven tool use—**evidence stays on the machine** |
| **Image intelligence** | AI-assisted image categorization for triage (weapons, documents, plates, CSAM-related classes, etc.) |
| **Multilingual UI** | Simplified Chinese, English, Japanese, Korean |


## Artifact coverage (representative)

### System & execution

Prefetch, BAM/DAM, AppCompat, Jump Lists, RecentDocs, ShellBags, LNK, UserAssist, UWP/AppX inventory, MRU keys, and related execution traces.

### Browsers & network

Chrome, Edge, Firefox (history, downloads, cookies, credentials, extensions), Zone.Identifier ADS, hosts/DNS/firewall artifacts.

### Communication

Foxmail, Outlook stores, WeChat/QQ/DingTalk/Feishu artifacts, Telegram Desktop, Discord, Signal, Skype, Teams, Zoom, and more.

### Cloud & remote access

OneDrive, Dropbox, Google Drive metadata, RDP history and bitmap cache, TeamViewer, AnyDesk, VPN profiles.

### Security & authentication

DPAPI master keys, Chrome Local State keys, Credential Manager, BitLocker recovery material, Wi‑Fi profiles, SSH configs.

### Logs & timeline

EVTX parsing and aggregation, Task Scheduler, BITS, Windows Update, PowerShell transcripts; cross-artifact timeline with correlation options.

### Deleted & hidden data

Recycle Bin, USN journal, extension/signature mismatches, high-entropy and encrypted container detection, duplicate file hashing.


## Case database & sessions

DigitalHound stores investigative output in a **portable case folder**:

- **`.dhcase`** — case metadata, evidence paths, bookmarks, audit log, view state
- **`case.db`** — SQLite database (WAL) with `dh_*` tables for artifacts, timeline, keywords, scan sessions

Reopen a case to **restore the forensic module tree**, filter by **scan session**, reload **timeline** and **search hits**, without re-scanning the image. This mirrors industry tools (Autopsy / AXIOM) while keeping your data under your control.


## AI forensic assistant (offline-first)

- Run **local** large language models—no mandatory cloud API
- Ask in plain language; the engine can invoke registered forensic tools
- Turn raw hits into structured summaries with timelines and highlighted risk items
- Extend behavior by registering tools on `ForensicAiEngine`

Example intents: encrypted archives, browser secrets, suspicious domains, image triage, consolidated timeline export.


## Reporting & chain of custody

- **CSV** — module or category exports
- **HTML** — interactive review in any browser
- **PDF** — case overview, sources, artifact summaries, bookmarks
- **Bookmarks** — severity tiers (critical / review / verified / reference)
- **Audit log** — actions recorded in the case file
- **Image hashing** — MD5 / SHA-256 (and related) integrity documentation


## Technical specifications

| Item | Support |
|------|---------|
| **Image formats** | RAW, DD, E01/E01-style, VHD/VHDX, VMDK, QCOW, AFF4 (via integrated libraries) |
| **File systems** | NTFS, FAT, exFAT, HFS+, APFS, ext2/3/4, and others via TSK |
| **Case store** | SQLite; optional SQLCipher path where enabled in build |
| **AI runtime** | llama.cpp, GGUF; optional OpenAI-compatible API |
| **Platform** | Windows 10/11 x64 (primary); portable deployment |


## Roadmap highlights

Capabilities actively extended in the product line include **DPAPI decryption chains**, **Telegram Desktop offline decryption**, **WeChat/QQ key acquisition workflows**, and deeper **mobile/cloud** companion products (**DigitalHound Mobile**, **DigitalHound Cloud**—separate SKUs).


## Get started

1. Acquire a forensic image (e.g. with **DigitalImager**).
2. Create a case and add the image path.
3. Run **Automatic Forensic Scan** (or pick modules from the catalog).
4. Explore **Forensic Results**, **Timeline View**, and **Search Hits**.
5. Export reports and archive the case folder for retention.


Digivetus Factium — leave no byte unexplored</strong><br/>

DigitalHound白皮书

Download the product white paper for full specifications and use cases

Download