Offline-first
Core evidence processing is designed to run on the analyst workstation.
TVAK Security
TVAK Collector for Windows available · TVAK Analyst in development
Collect evidence, reconstruct timelines, connect artifacts, and investigate incidents through a unified, offline-first DFIR workflow.
Transparent findings with rule and evidence context.
Case activeT1059.00196%T106092%T1071.00191%T1021.00278%10 modules collected using VSS-assisted acquisition with live fallback available.
Built for consequential work
TVAK Security is building privacy-conscious investigation tools for incident responders, forensic investigators, threat hunters, and enterprise security teams.
Core evidence processing is designed to run on the analyst workstation.
Findings stay connected to source artifacts, rules, and confidence.
Proven links and contextual associations remain visibly distinct.
AI can assist reasoning and reporting without replacing analyst judgment.
One evidence-led workflow
Follow a representative investigation through interfaces adapted from the real TVAK Evidence Collector for Windows and TVAK Analyst product designs.
TVAK Evidence Collector for Windows
Acquire volatile and persistent Windows artifacts without relying on a permanently installed endpoint agent.
TVAK Analyst
Open an existing case, import a structured package, or begin with evidence-grounded assistance.
Open a case to begin your investigation. You can open an existing case, import data, or use AI Analyst.
Open a case to begin your investigation. You can open an existing case, import data, or use AI Analyst to get started.
Continue an existing extracted investigation.
Import a .tvak package or add a new host.
Use evidence-grounded assistance to get started.
ⓘ Tip: use the left navigation to explore analysis tools.
TVAK Analyst
Review severity, the detection explanation, rule, confidence, supporting evidence, ATT&CK context, and analyst status.
Transparent findings with rule and evidence context.
Case activeT1059.00196%T106092%T1071.00191%T1021.00278%Timeline Explorer
Align Prefetch, MFT, event logs, processes, services, scheduled tasks, registry, and network evidence.
WKSTN-07 · 1,285 events across forensic sources.
Case activeArtifact Relationship Graph
Keep proven relationships, linked evidence, and contextual associations visibly distinct.
Explore extracted relationships without overstating causality.
Case activeAI Investigation
Review cited summaries, hypotheses, conflicting evidence, and recommended next steps before approval.
Evidence-grounded assistance with analyst review.
Case activeSupported by process, registry, prefetch, and network evidence.
[1] EVT-00182 [2] REG-00041 [3] NET-00214No interactive remote logon was recorded during the incident window.
Analyst review requiredTVAK Analyst
Assemble findings, timelines, references, indicators, ATT&CK mapping, recommendations, and export options.
Analyst-reviewed reporting with linked evidence.
Case activeAnalysis identified an encoded command, a new executable, and a registry Run key.
Primary products
Collector acquires selected Windows evidence. Analyst turns that structured package into a local, evidence-backed investigation.
Available · Open Source · Windows
TVAK / Collector
A lightweight Windows forensic evidence and artifact acquisition tool for collecting selected endpoint artifacts and creating structured evidence packages without requiring a permanently installed endpoint agent.
Windows release available now. Linux support is in development.
In Development
Open a case to begin your investigation. You can open an existing case, import data, or use AI Analyst.
Open a case to begin your investigation. You can open an existing case, import data, or use AI Analyst to get started.
Continue an existing extracted investigation.
Import a .tvak package or add a new host.
Use evidence-grounded assistance to get started.
ⓘ Tip: use the left navigation to explore analysis tools.
TVAK / Analyst
An offline-first DFIR investigation workspace for triage, evidence review, timeline reconstruction, artifact relationships, assisted investigation, and reporting.
Collector → Analyst
Collector for Windows runs on the endpoint or evidence source, produces a structured package, and hands that package to Analyst. Investigation remains local and the evidence stays under analyst control.
10 modules collected using VSS-assisted acquisition with live fallback available.
Open a case to begin your investigation. You can open an existing case, import data, or use AI Analyst.
Open a case to begin your investigation. You can open an existing case, import data, or use AI Analyst to get started.
Continue an existing extracted investigation.
Import a .tvak package or add a new host.
Use evidence-grounded assistance to get started.
ⓘ Tip: use the left navigation to explore analysis tools.
01Endpoint or evidence source
02Integrity recorded
03Local investigation
Core capabilities
Capabilities are grouped by investigative purpose, with acquisition and evidence review taking priority over speculative automation.
Future product direction
These concepts describe future direction. They are not currently available for download or production use.
Planned
TVAK / IntelligenceA threat intelligence operating environment centered on context, actionability, and investigation workflows.
Concept · future direction
Future Roadmap
TVAK / Live ResponseA future extension for controlled remote collection, endpoint triage, and case-based response workflows.
Concept · future directionArchitecture & privacy
Core evidence processing is designed to occur locally by default. External services, including AI APIs, remain optional and must be explicitly configured.
ORGANISATION-CONTROLLED BOUNDARY
Resources
Resource categories are being prepared. No placeholder title below is presented as a published article.
DFIR Guides
Incident Response
Windows Forensics
Threat Hunting
Product Updates
Clear answers
What enterprise security teams should know about TVAK’s current direction and product status.
TVAK Evidence Collector for Windows is available now as an open-source download. Linux support and TVAK Analyst remain in development, while other platform capabilities are planned or on the future roadmap.
TVAK is being designed as an offline-first platform. Core investigation and evidence processing are intended to run locally by default.
Not by default. External services should only be used when an organization explicitly configures them.
No. TVAK is intended to complement endpoint, SIEM, and security monitoring platforms through evidence collection, correlation, and forensic analysis.
No. AI capabilities are intended to assist with summaries, correlation, hypotheses, and reporting while keeping decisions under analyst control.
The platform is being designed with offline and isolated investigation environments in mind.
Contact & Analyst early access
TVAK Evidence Collector for Windows is available now. TVAK Analyst remains in development. Contact us about Analyst early access, future products, or general enquiries.