Arcana-Forensics delivers the investigative capability of enterprise forensic suites — artifact collection, parsing, timeline analysis, and chain-of-custody reporting — with the user in full control. Everything runs locally: no cloud, no telemetry, and case data never leaves your machine.
Built for individuals, startups, non-profits, home labs, schools, and security teams who need results without handing their evidence to a third party.
Live suite: https://arcana-forensics.com Docs + Changelog: https://arcana-forensics.com/CHANGELOG.md
Free tools stay free. Pro keeps the lights on.
1. Arcana-Forensics Triage — FREE FOREVER (was linuxforensics) Quick, safe check when Linux feels off. For home users, students, small shops.
- Collects processes & logs, creates a defensible report
- Offline, read-only, evidence-grade
- Nothing is uploaded — analysis and output stay on your workstation
2. Arcana-Forensics Crucible Pro — Lifetime License (was credentialauditor) Find weak, reused, and breached passwords before attackers do — plus the full forensic pipeline.
- Up to 500 users, offline, one-click owner report
- Chain-of-custody JSONL, SHA-256 verified, UTC timestamps
- Prioritizes what to fix first
- Current pricing: https://arcana-forensics.com
Why offline matters: forensic evidence routinely contains credentials, client data, and trade secrets. Air-gapped analysis removes the network paths where breaches and leaks happen — and keeps the chain of custody in your hands, not a vendor's.
Philosophy: Offline First. Defensible Reports. No Vendor Lock-In.
Download from releases or run locally:
./arcana-triage/run.sh
./arcana-crucible/run.sh --scan sample/creds.txt
./scripts/generate_sha256sums.py
./qa/verify_all.sh