What brings you to SUSA?
Prepare a Windows DFIR workstation, follow a practical investigation path, or go directly to the utility you need.
From workstation to supported findings
SUSA connects environment preparation, evidence acquisition, focused analysis and timeline reconstruction so each stage can build on the last.
Build a Windows VM, install WSL, improve forensic visibility and create shortcuts.
Prepare the environmentChoose live-response, disk-acquisition or memory-acquisition tools for the task.
Explore evidence collectionWork through disk, file-system, browser, Registry, event-log and memory evidence.
Explore host and storage analysisCombine file-system and event evidence into an ordered, reviewable timeline.
Explore threat and timeline analysisChoose a first practical guide
Filter these starting points by investigation goal, then open a practical SUSA guide with a defined evidence-focused outcome.
4 recommended guides
KAPE
Collect and process targeted forensic artefacts from a Windows system.
Focus: targeted acquisition and processing.
Autopsy
Open and examine forensic data using an established disk-analysis workflow.
Focus: disk images and recovered evidence.
Volatility and Workbench
Investigate a memory image with Volatility and its Workbench interface.
Focus: processes and volatile evidence.
Wireshark
Inspect packet captures, follow conversations and extract useful network evidence.
Focus: traffic analysis and reconstruction.
Explore the SUSA toolkit
Start with an investigation family, then open the evidence source or utility that matches your task.
Evidence Collection
Collect live system state, disk data and volatile memory before moving into analysis.
Host & Storage Analysis
Recover files and interpret persistent Windows, NTFS, browser and Registry evidence.
Volatile & Network Analysis
Review recorded events, running state and communications from complementary evidence sources.
Threat & Timeline Analysis
Order activity, inspect suspicious files and connect email evidence with the wider case.
Analyst Utilities
Inspect live Windows behaviour and complete common hashing, archive and working-data tasks.
Move through the forensic workflow
Use SUSA to prepare the environment, collect evidence, examine artefacts and reconstruct activity with documented, repeatable steps.