Drop a triage collection. Read the whole story.
Sootmark runs every artifact parser on your KAPE or Velociraptor collection, merges the results into one super-timeline and surfaces corroborated findings, each one linked to its raw bytes. On your laptop. Nothing leaves your machine.
No upload · Works air-gapped · Built for IR consultants and boutique firms
| Time (UTC) | Artifact | Host | Event |
|---|---|---|---|
| 03:11:58 | EVTX 4624 | WS-042 | Logon type 10 · svc_backup from 10.0.4.17 |
| 03:12:07 | Prefetch | WS-042 | RCLONE.EXE executed · run count 3 |
| 03:12:07 | AmCache | WS-042 | rclone.exe first seen · SHA1 4f2e…a91c |
| 03:12:09 | EVTX 4688 | WS-042 | rclone.exe copy \\FS01\finance remote: |
| 03:14:51 | EVTX 4624 | FS01 | Logon type 3 from WS-042 · svc_backup |
| 03:15:02 | USN | FS01 | 1,284 files renamed → *.locked |
HighExfiltration tool executed
Prefetch, AmCache, Security 4688 and USN agree: rclone.exe ran on WS-042 at 03:12, then touched FS01 over SMB.
The problem
Investigations are multi-artifact. Your tools aren't.
A typical triage means juggling a collector, a dozen single-purpose parsers, a CSV viewer, an EVTX hunter and a spreadsheet for notes. Or paying thousands per seat for a heavyweight suite.
- Hours of processing before the first real answer
- Findings spread across CSVs, screenshots and notes
- Corroboration across artifacts done by hand
- Cloud tools ruled out by client contracts
How it works
From collection to report in four steps
- 01
Intake
Drop a KAPE or Velociraptor collection, a disk image or loose artifacts. Types are detected by path and magic bytes.
- 02
Parse
Every parser runs in parallel, locally. Per-artifact progress and errors, nothing hidden.
- 03
Correlate
One normalized super-timeline across hosts. Hunts run automatically and cross-check artifacts.
- 04
Report
Bookmark findings and export a report with evidence hashes, tool versions and links to raw records.
Features
One workbench for the whole triage
Everything flows into one case history, and every tool works on it. No more exporting CSVs between tools.
Super-timeline
Every event from every artifact and every host in one fast, filterable table with a histogram.
Corroborated findings
Cross-artifact rules confirm execution, logons and persistence when several sources agree.
Query language
Search every artifact at once with one syntax: artifact:prefetch user:alice path:*\Temp\*
Inspector
Open any record and see raw bytes next to decoded fields. Re-parse with other options.
Hunt packs
EVTX hunts plus cross-artifact rules, run on intake. Bring your own IOC lists and rules.
Evidence-linked reports
Every claim in the report points to its raw record, with SHA-256 hashes of the evidence.
Trust
Built for findings you can defend
A forensic tool is only worth what you can explain in a report, to a client, an insurer or a court.
Local by design
No upload, no telemetry by default. The desktop build runs with the network cable unplugged.
Explainable
No black-box scores. Every finding shows the rules and the raw records behind it.
Reproducible
Reports record tool and parser versions, input hashes and settings, so a peer gets the same output.
No lock-in
An open, documented case format, plus exports to CSV, Timesketch and your report template.
Workflow
Fits the pipeline you already have
Keep your collector and your report template. Sootmark replaces the processing and first-look analysis in between.
Takes in
- KAPE (folder, zip, VHDX)
- Velociraptor
- E01 / raw images
- Loose artifacts
- EZ Tools CSV
Hands off to
- CSV
- Timesketch
- STIX / MISP
- DOCX / PDF report
- IRIS / TheHive
Pricing
Simple pricing, no sales call
Buy with a card in the middle of an incident. Monthly plans for contractors.
Free
€0
Single-artifact parsers in the browser.
- One artifact type at a time
- Runs in your browser, no upload
- Great for quick checks
Pro
€99/month
For the solo analyst. Or €990/year.
- Unlimited collections and hosts
- Super-timeline and query language
- Cross-artifact findings and hunts
- Reports with evidence hashes
Team
€1,490/seat/year
For IR firms and MSSPs.
- Everything in Pro
- Shared case files
- Custom hunt packs and templates
- Priority support
Offline
Custom
Perpetual license for air-gapped labs.
- Signed offline license key
- Perpetual license + maintenance
- Validation kit for your lab
Planned pricing, shown for early access. Subject to change before launch. Free licenses planned for students, academia and law enforcement.
FAQ
Questions analysts ask
Does my evidence ever leave my machine?
No. Parsing, the timeline and hunts all run locally, in your browser or in the desktop app. There is no upload step and no telemetry by default.
Which artifacts are supported?
Windows triage first: Event Logs, MFT, USN journal, Prefetch, AmCache, ShimCache, registry hives, LNK, Jump Lists, SRUM, Recycle Bin, browser history and more, around twenty artifact types.
Which collection formats can I load?
KAPE output (folder, zip or VHDX), Velociraptor offline collections, E01 and raw disk images, and loose artifact files.
Does it replace AXIOM or X-Ways?
Not on day one, and it doesn't have to. Many analysts start by using Sootmark as a fast first look or as a second tool to cross-check key findings.
When can I use it?
Sootmark is in early development. Join the waitlist to get early access and to help shape the first release.
Is there a discount for students or law enforcement?
Yes. Free licenses are planned for students, academia and law enforcement.
Stop stitching tools together.
Join the waitlist for early access. We'll only email you about Sootmark.
Join the waitlist