TVAK Security

TVAK Collector for Windows available · TVAK Analyst in development

Investigate
with clarity.

Collect evidence, reconstruct timelines, connect artifacts, and investigate incidents through a unified, offline-first DFIR workflow.

Offline-first by designEvidence under analyst controlHuman-led, AI-assisted
TVAK ANALYSTINVESTIGATION CONSOLEFile  Edit  View  Case  Tools  HelpCASECASE-2026-014

Triage Findings

Transparent findings with rule and evidence context.

Case active
OPEN FINDINGS06CRITICAL01HIGH03ANALYST STATUSIn review
FINDINGSEVERITYRULECONFIDENCE
Encoded PowerShell executionSupporting evidence availableCriticalT1059.00196%
Persistence via Run keySupporting evidence availableHighT106092%
Beaconing to known C2Supporting evidence availableHighT1071.00191%
Remote service creationSupporting evidence availableMediumT1021.00278%
Detection explanationCommand-line, process parent, network, and file evidence support this finding.MITRE ATT&CK mapped
ReadyWKSTN-07 · local caseZoom −  + 100%
TVAKEVIDENCE COLLECTORSTATUSCompleteTARGETWKSTN-07
1Select2Configure3Collect
COLLECTION COMPLETE

Evidence package ready

10 modules collected using VSS-assisted acquisition with live fallback available.

PACKAGEWKSTN-07_2026-07-26.tvakINTEGRITYSHA-256 recordedARTIFACTS1,284 files
100%
Package written successfullyAvailable · Open Source · Windows

Built for consequential work

Evidence, privacy, and clarity by design.

TVAK Security is building privacy-conscious investigation tools for incident responders, forensic investigators, threat hunters, and enterprise security teams.

01

Offline-first

Core evidence processing is designed to run on the analyst workstation.

02

Evidence-led

Findings stay connected to source artifacts, rules, and confidence.

03

Transparent

Proven links and contextual associations remain visibly distinct.

04

Human-led

AI can assist reasoning and reporting without replacing analyst judgment.

One evidence-led workflow

From endpoint collection to a defensible report.

Follow a representative investigation through interfaces adapted from the real TVAK Evidence Collector for Windows and TVAK Analyst product designs.

01

TVAK Evidence Collector for Windows

Collect

Collect only the evidence the investigation needs.

Acquire volatile and persistent Windows artifacts without relying on a permanently installed endpoint agent.

TVAKEVIDENCE COLLECTORSTATUSReadyTARGETWKSTN-07
1Select2Configure3Collect
SELECT EVIDENCEEvidence modules10 selected
SystemOS, boot and device historyReady
ProcessesPaths, parents, hashes and signaturesAlways
NetworkTCP connections and owning processReady
ServicesState, start mode and accountReady
PersistenceRun keys, WMI and startup itemsReady
Scheduled TasksAuthors, actions and signaturesReady
Event LogsSecurity, System and PowerShellReady
Raw DataMFT, USN, Prefetch and hivesReady
Elevated · Raw / VSS availableAvailable · Open Source · Windows
Next: Import
02

TVAK Analyst

Import

Move evidence into a structured investigation workspace.

Open an existing case, import a structured package, or begin with evidence-grounded assistance.

TVAK ANALYSTINVESTIGATION CONSOLEFile  Edit  View  Case  Tools  HelpCASENo case open

No case open

Open a case to begin your investigation. You can open an existing case, import data, or use AI Analyst.

No case open

Open a case to begin your investigation. You can open an existing case, import data, or use AI Analyst to get started.

Open Case

Continue an existing extracted investigation.

Start with AI Analyst

Use evidence-grounded assistance to get started.

ⓘ Tip: use the left navigation to explore analysis tools.

ReadyNo case openZoom −  + 100%
Next: Triage
03

TVAK Analyst

Triage

Prioritise transparent, evidence-backed findings.

Review severity, the detection explanation, rule, confidence, supporting evidence, ATT&CK context, and analyst status.

TVAK ANALYSTINVESTIGATION CONSOLEFile  Edit  View  Case  Tools  HelpCASECASE-2026-014

Triage Findings

Transparent findings with rule and evidence context.

Case active
OPEN FINDINGS06CRITICAL01HIGH03ANALYST STATUSIn review
FINDINGSEVERITYRULECONFIDENCE
Encoded PowerShell executionSupporting evidence availableCriticalT1059.00196%
Persistence via Run keySupporting evidence availableHighT106092%
Beaconing to known C2Supporting evidence availableHighT1071.00191%
Remote service creationSupporting evidence availableMediumT1021.00278%
Detection explanationCommand-line, process parent, network, and file evidence support this finding.MITRE ATT&CK mapped
ReadyWKSTN-07 · local caseZoom −  + 100%
Next: Reconstruct
04

Timeline Explorer

Reconstruct

Reconstruct activity across forensic evidence sources.

Align Prefetch, MFT, event logs, processes, services, scheduled tasks, registry, and network evidence.

TVAK ANALYSTINVESTIGATION CONSOLEFile  Edit  View  Case  Tools  HelpCASECASE-2026-014

Timeline Explorer

WKSTN-07 · 1,285 events across forensic sources.

Case active
All sourcesPrefetchMFTEvent logsRegistryNetwork
Event LogInteractive user logonEvidence
Processpowershell.exe launched encoded commandFinding
PrefetchPOWERSHELL.EXE execution recordedEvidence
RegistryRun key value modifiedEvidence
NetworkOutbound connection to 185.220.101.23Evidence
ReadyWKSTN-07 · local caseZoom −  + 100%
Next: Connect
05

Artifact Relationship Graph

Connect

Connect related evidence without overstating causality.

Keep proven relationships, linked evidence, and contextual associations visibly distinct.

TVAK ANALYSTINVESTIGATION CONSOLEFile  Edit  View  Case  Tools  HelpCASECASE-2026-014

Artifact Relationship Graph

Explore extracted relationships without overstating causality.

Case active
Proven relationshipLinked relationshipContextual association
UserJ.DoeProcesspowershell.exeHostWKSTN-07Filepayload.exeTaskUpdaterTaskServiceUpdaterSvcIP address185.220.101.23Registry keyRun\Updater
ReadyWKSTN-07 · local caseZoom −  + 100%
Next: Investigate
06

AI Investigation

Investigate

Use evidence-grounded assistance while the analyst stays in control.

Review cited summaries, hypotheses, conflicting evidence, and recommended next steps before approval.

TVAK ANALYSTINVESTIGATION CONSOLEFile  Edit  View  Case  Tools  HelpCASECASE-2026-014

AI Analyst

Evidence-grounded assistance with analyst review.

Case active
INVESTIGATION SUMMARY
Likely scripted persistence following an encoded PowerShell execution.

Supported by process, registry, prefetch, and network evidence.

[1] EVT-00182 [2] REG-00041 [3] NET-00214
HYPOTHESES
01Initial access via downloaded scriptHigh confidence
02Persistence through user Run keySupported
CONFLICTING EVIDENCE

No interactive remote logon was recorded during the incident window.

Analyst review required
Recommended next stepsReview script contentsValidate destination IPConfirm task creator
ReadyWKSTN-07 · local caseZoom −  + 100%
Next: Report
07

TVAK Analyst

Report

Turn case evidence into clear technical and executive reporting.

Assemble findings, timelines, references, indicators, ATT&CK mapping, recommendations, and export options.

TVAK ANALYSTINVESTIGATION CONSOLEFile  Edit  View  Case  Tools  HelpCASECASE-2026-014

Investigation Report

Analyst-reviewed reporting with linked evidence.

Case active
EXECUTIVE SUMMARY
Suspicious PowerShell activity established user-level persistence.

Analysis identified an encoded command, a new executable, and a registry Run key.

Finding 01Encoded PowerShell execution4 evidence references
ATT&CKT1059.001 · T1060Mapped
RecommendationIsolate the affected host and validate the persistence path.
EXPORT
ReadyWKSTN-07 · local caseZoom −  + 100%
0107
TVAKEVIDENCE COLLECTORSTATUSReadyTARGETWKSTN-07
1Select2Configure3Collect
SELECT EVIDENCEEvidence modules10 selected
SystemOS, boot and device historyReady
ProcessesPaths, parents, hashes and signaturesAlways
NetworkTCP connections and owning processReady
ServicesState, start mode and accountReady
PersistenceRun keys, WMI and startup itemsReady
Scheduled TasksAuthors, actions and signaturesReady
Event LogsSecurity, System and PowerShellReady
Raw DataMFT, USN, Prefetch and hivesReady
Elevated · Raw / VSS availableAvailable · Open Source · Windows

Primary products

Two focused tools.
One investigation path.

Collector acquires selected Windows evidence. Analyst turns that structured package into a local, evidence-backed investigation.

01 / PRIMARY PRODUCT

Available · Open Source · Windows

TVAKEVIDENCE COLLECTORSTATUSReadyTARGETWKSTN-07
1Select2Configure3Collect
SELECT EVIDENCEEvidence modules10 selected
SystemOS, boot and device historyReady
ProcessesPaths, parents, hashes and signaturesAlways
NetworkTCP connections and owning processReady
ServicesState, start mode and accountReady
PersistenceRun keys, WMI and startup itemsReady
Scheduled TasksAuthors, actions and signaturesReady
Event LogsSecurity, System and PowerShellReady
Raw DataMFT, USN, Prefetch and hivesReady
Elevated · Raw / VSS availableAvailable · Open Source · Windows

TVAK / Collector

TVAK Evidence Collector for Windows

A lightweight Windows forensic evidence and artifact acquisition tool for collecting selected endpoint artifacts and creating structured evidence packages without requiring a permanently installed endpoint agent.

Windows release available now. Linux support is in development.

  • Open source
  • GUI + CLI
  • Selective collection
  • Evidence packaging
  • VSS-aware acquisition
  • Integrity metadata
  • Optional memory
02 / PRIMARY PRODUCT

In Development

TVAK ANALYSTINVESTIGATION CONSOLEFile  Edit  View  Case  Tools  HelpCASENo case open

No case open

Open a case to begin your investigation. You can open an existing case, import data, or use AI Analyst.

No case open

Open a case to begin your investigation. You can open an existing case, import data, or use AI Analyst to get started.

Open Case

Continue an existing extracted investigation.

Start with AI Analyst

Use evidence-grounded assistance to get started.

ⓘ Tip: use the left navigation to explore analysis tools.

ReadyNo case openZoom −  + 100%

TVAK / Analyst

TVAK Analyst

An offline-first DFIR investigation workspace for triage, evidence review, timeline reconstruction, artifact relationships, assisted investigation, and reporting.

  • Triage findings
  • Timeline Explorer
  • Evidence Explorer
  • Artifact Graph
  • AI Investigation
  • Reporting

Collector → Analyst

Evidence moves.
Control does not.

Collector for Windows runs on the endpoint or evidence source, produces a structured package, and hands that package to Analyst. Investigation remains local and the evidence stays under analyst control.

TVAKEVIDENCE COLLECTORSTATUSCompleteTARGETWKSTN-07
1Select2Configure3Collect
COLLECTION COMPLETE

Evidence package ready

10 modules collected using VSS-assisted acquisition with live fallback available.

PACKAGEWKSTN-07_2026-07-26.tvakINTEGRITYSHA-256 recordedARTIFACTS1,284 files
100%
Package written successfullyAvailable · Open Source · Windows
PACKAGE READYWKSTN-07_2026-07-26.tvakIntegrity recorded1,284 artifactsCollection log includedImported → Case available
TVAK ANALYSTINVESTIGATION CONSOLEFile  Edit  View  Case  Tools  HelpCASENo case open

No case open

Open a case to begin your investigation. You can open an existing case, import data, or use AI Analyst.

No case open

Open a case to begin your investigation. You can open an existing case, import data, or use AI Analyst to get started.

Open Case

Continue an existing extracted investigation.

Start with AI Analyst

Use evidence-grounded assistance to get started.

ⓘ Tip: use the left navigation to explore analysis tools.

ReadyNo case openZoom −  + 100%

01Endpoint or evidence source

02Integrity recorded

03Local investigation

Core capabilities

A modular path through the case.

Capabilities are grouped by investigative purpose, with acquisition and evidence review taking priority over speculative automation.

01

Acquire

  • Evidence Collection
  • Selective Windows Artifacts
  • VSS-aware Acquisition
  • Memory Capture
02

Analyse

  • Triage Findings
  • Timeline Explorer
  • Evidence Explorer
  • Registry & Network Analysis
03

Correlate

  • Artifact Relationship Graph
  • Cross-source Timelines
  • MITRE ATT&CK Context
04

Investigate

  • Script & File Analysis
  • Decoder
  • Email Header Analysis
  • AI Investigation
05

Report

  • Executive Summary
  • Technical Findings
  • Evidence References
  • Recommendations

Future product direction

Roadmap products,
clearly distinguished.

These concepts describe future direction. They are not currently available for download or production use.

Planned

TVAK / Intelligence

TVAK Threat Intelligence

A threat intelligence operating environment centered on context, actionability, and investigation workflows.

Concept · future direction
TVAK Live Response future interface concept

Future Roadmap

TVAK / Live Response

TVAK Live Response

A future extension for controlled remote collection, endpoint triage, and case-based response workflows.

Concept · future direction

Architecture & privacy

Evidence stays close.
Control stays with you.

Core evidence processing is designed to occur locally by default. External services, including AI APIs, remain optional and must be explicitly configured.

  • Investigation engine runs on the analyst workstation
  • Evidence is not automatically uploaded externally
  • Local models and external APIs remain clearly distinguished
01Evidence sourceSelected Windows artifacts
02TVAK packageManifest, hashes, collection log
03Local AnalystParse, correlate, investigate

ORGANISATION-CONTROLLED BOUNDARY

Resources

Practical guidance for better investigations.

Resource categories are being prepared. No placeholder title below is presented as a published article.

01

DFIR Guides

Building a Defensible Incident Timeline

Coming soon
02

Incident Response

Why Artifact Correlation Matters in DFIR

Coming soon
03

Windows Forensics

Evidence Collection Without a Permanent Agent

Coming soon
04

Threat Hunting

Transparent Findings for Threat Hunters

Coming soon
05

Product Updates

Inside the TVAK Investigation Workflow

Coming soon

Clear answers

Frequently asked questions.

What enterprise security teams should know about TVAK’s current direction and product status.

01Is TVAK available today?+

TVAK Evidence Collector for Windows is available now as an open-source download. Linux support and TVAK Analyst remain in development, while other platform capabilities are planned or on the future roadmap.

02Is TVAK cloud-based?+

TVAK is being designed as an offline-first platform. Core investigation and evidence processing are intended to run locally by default.

03Does TVAK upload evidence externally?+

Not by default. External services should only be used when an organization explicitly configures them.

04Does TVAK replace an EDR or SIEM?+

No. TVAK is intended to complement endpoint, SIEM, and security monitoring platforms through evidence collection, correlation, and forensic analysis.

05Is TVAK an autonomous AI investigator?+

No. AI capabilities are intended to assist with summaries, correlation, hypotheses, and reporting while keeping decisions under analyst control.

06Can TVAK work in restricted environments?+

The platform is being designed with offline and isolated investigation environments in mind.

Contact & Analyst early access

Bring clarity to your next investigation.

TVAK Evidence Collector for Windows is available now. TVAK Analyst remains in development. Contact us about Analyst early access, future products, or general enquiries.

contact@tvaksecurity.com