A technical and restrained view of how PowerForensics public tools relate to each other.

Native and portable tooling for live triage and rapid acquisition on Windows, Linux, and IoT.
Conversion and normalization of evidence or logs into structures consumable across the ecosystem.
Timeline reconstruction to order events, sequences, and relevant activity during an investigation.
Graph-based relational analysis to represent links between entities, artifacts, systems, users, and events.
Capture relevant artifacts with PowerTriage in the appropriate technical context.
Prepare evidence and logs with PowerLens to simplify filtering, reading, and reuse.
Rebuild the event sequence with Chronos to identify transitions, pivots, and key moments.
Explore dependencies and links with Nexus across users, systems, artifacts, and events.
Live triage and artifact acquisition in Windows environments.
Fast triage and structured acquisition in Linux systems.
Technical review of IoT devices and embedded platforms.
Normalization and data preparation for later technical consumption.
Timeline-oriented review for event and activity reconstruction.
Relational visualization of entities, artifacts, and events.