“What does this artifact actually prove?”
Where 14 Windows artifacts live, what each one establishes, and what it does not. That second half is the reason it exists: most references stop at what an artifact shows, which is how “Shimcache proves execution” became the most repeated mistake in the field.
6 categories, from execution to anti-forensics. 4 free to read.
“What should I collect, and what is expiring?”
Pick what you are trying to establish and get the sources that would establish it, in collection order, with the volatile ones first. Each one also names the trap: the source people reach for that does not settle the question.
8 hypotheses, free to use
“What is this timestamp, and is this link safe?”
Timestamp conversion, defanging, and link checks. Everything runs in your browser and nothing is sent anywhere, which is the point: the paste-it-into-a-website tools you reach for during an incident are the ones you should not paste evidence into.
Free, no account
“Where do I get tools, feeds and practice data?”
Advisories worth reading as they publish, the tooling to have installed before you need it, and public datasets to practise on. Other people’s work, collected because it is good, not because we made it.
Free, no account
for teams
The Threat Wire is also available as an API, in JSON, CSV or STIX 2.1, for pulling into a SOAR playbook or a dashboard. The documentation is public, including the rate limits and the error codes, so you can plan a pipeline before buying anything.
not sure which?
If you have a host in front of you and a question about it, start with the evidence-gap checker: it will hand you a collection list and link into the reference for each item. If you have already collected and want to know what a finding means, go straight to the artifact reference.
Learning rather than working? Start here instead.