Offline-first
Core evidence processing is designed to run on the analyst workstation.
Platform currently in development
Collect evidence, reconstruct timelines, connect artifacts, and understand security incidents from one unified DFIR workspace.
Built for consequential work
TVAK is being designed for security teams that need a technically honest path from fragmented artifacts to defensible response decisions.
Core evidence processing is designed to run on the analyst workstation.
Findings stay connected to their source artifacts, rules, and confidence.
Proven links and contextual associations remain visibly distinct.
AI assists with reasoning and reporting without replacing judgment.
Specialized tools can operate independently or share one case model.
One investigation flow
Follow a fictional investigation as TVAK products bring evidence, context, and analyst decisions into one connected workspace.
TVAK Evidence Collector
Collect volatile and persistent Windows artifacts without relying on a permanently installed endpoint agent.
TVAK Analyst
See why an activity was flagged, the rule that produced it, its source evidence, confidence, and ATT&CK context.
Timeline Explorer
Align execution, filesystem, event log, service, registry, and network activity on one investigation timeline.
Artifact Relationship Graph
Explore files, users, processes, services, hosts, IP addresses, and registry keys with proven and contextual links kept distinct.
AI Investigation
Review evidence-aware summaries, competing hypotheses, conflicting signals, and recommended next steps before accepting them.
Investigation Reports
Keep summaries, findings, timelines, indicators, ATT&CK mappings, and evidence references connected to the case.
TVAK EVIDENCE COLLECTOR
Product ecosystem
Each TVAK product is being designed to operate independently while sharing investigation, timeline, relationship, and reporting concepts.
In Development
TVAK / Collector
A lightweight Windows acquisition tool for collecting forensic artifacts and creating structured evidence packages.
In Development
TVAK / Analyst
An offline-first DFIR workspace for triage, timelines, artifact relationships, investigation, and reporting.
Planned
TVAK / Intelligence
A threat intelligence operating environment centered on context, actionability, and investigation workflows.
Future Roadmap
TVAK / Live Response
A future extension for controlled remote collection, endpoint triage, and case-based response workflows.
Architecture & privacy
Core evidence processing is designed to occur locally by default. External services, including AI APIs, are optional and must be explicitly configured.
Product direction
Progress is communicated by validated capability stages—not fixed release-date promises.
The evidence, case, local engine, and Windows acquisition model.
Evidence packages · Case model · Core parsersTransparent triage, connected timelines, exploration, and reporting.
Triage findings · Timeline Explorer · Artifact graphDeeper memory, malware, registry, network, and script analysis.
Memory analysis · Malware analysis · CorrelationEvidence-aware assistance for summaries, hypotheses, and next steps.
Local AI support · Hypotheses · NarrativesRoadmap items reflect current product direction and may evolve based on technical validation, security requirements, and customer feedback.
Field notes
Sample editorial topics for a future TVAK resource library. No research claims or published articles are implied.
DFIR Guides · Coming soon
Incident Response · Coming soon
Architecture · Coming soon
Clear answers
What enterprise security teams should know about TVAK’s current direction and product status.
TVAK products are at different stages of development. Evidence Collector and TVAK Analyst are under active development; other platform capabilities remain planned or on the future roadmap.
TVAK is being designed as an offline-first platform. Core investigation and evidence processing are intended to run locally by default.
Not by default. External services should only be used when an organization explicitly configures them.
No. TVAK is intended to complement endpoint, SIEM, and security monitoring platforms through evidence collection, correlation, and forensic analysis.
No. AI capabilities are intended to assist with summaries, correlation, hypotheses, and reporting while keeping decisions under analyst control.
The platform is being designed with offline and isolated investigation environments in mind.
Early access
Enterprise security teams can register interest in TVAK Analyst, Evidence Collector, or the wider investigation platform.