Windows DFIR workstation & practical guides

SUSA

Security Utility Suite for Analysts

A purpose-built Windows DFIR workstation and practical documentation platform for evidence collection, investigation and forensic analysis.

Scroll to explore

About SUSA

SUSA, the Security Utility Suite for Analysts, brings practical Windows digital-forensics and incident-response utilities together in a purpose-built analyst workstation.

The documentation follows the intended investigation sequence from environment preparation and evidence collection through artefact analysis, memory and network investigation, timeline reconstruction and reporting. The result is a single, evidence-led route from first collection to a reviewable analyst finding.

Start your way

What brings you to SUSA?

Prepare a Windows DFIR workstation, follow a practical investigation path, or go directly to the utility you need.

A practical investigation path

From workstation to supported findings

SUSA connects environment preparation, evidence acquisition, focused analysis and timeline reconstruction so each stage can build on the last.

Create a forensic workstation

Build a Windows VM, install WSL, improve forensic visibility and create shortcuts.

Prepare the environment
Recommended starting points

Choose a first practical guide

Filter these starting points by investigation goal, then open a practical SUSA guide with a defined evidence-focused outcome.

What do you want to practise?

4 recommended guides

Evidence collectionPractical guide

KAPE

Collect and process targeted forensic artefacts from a Windows system.

Focus: targeted acquisition and processing.

Windows workstationGuided workflow
Disk analysisPractical guide

Autopsy

Open and examine forensic data using an established disk-analysis workflow.

Focus: disk images and recovered evidence.

Windows workstationGuided workflow
Memory analysisPractical guide

Volatility and Workbench

Investigate a memory image with Volatility and its Workbench interface.

Focus: processes and volatile evidence.

Memory imageGuided workflow
Network forensicsPractical guide

Wireshark

Inspect packet captures, follow conversations and extract useful network evidence.

Focus: traffic analysis and reconstruction.

Packet captureGuided workflow
Explore by evidence source

Explore the SUSA toolkit

Start with an investigation family, then open the evidence source or utility that matches your task.

One practical workstation

Move through the forensic workflow

Use SUSA to prepare the environment, collect evidence, examine artefacts and reconstruct activity with documented, repeatable steps.

Available nowPrepareCreate and configure the Windows forensic workstation.
Available nowCollectAcquire live, disk and memory evidence for analysis.
Available nowAnalyseExamine artefacts across systems, applications and memory.
Available nowCorrelateCombine evidence into an ordered reconstruction of activity.
Ownership & project terms

Copyright, ownership & licence

Copyright © 2024–2026 Joseph Jee. Original SUSA documentation is licensed under CC BY-NC 4.0; project identity and identified third-party material are excluded.

Ownership & licensingRead the full project terms