Windows DFIR workstation & practical guides

About SUSA

Learn what SUSA provides, who maintains the project, how its original documentation may be used, and which material remains outside the licence.

1independent owner CCBY-NC 4.0 documentation DFIRevidence-led learning
01

Project

Understand the role SUSA plays and the boundaries that remain around any forensic workflow.

Security Utility Suite for Analysts Focused tools, evidence-led guidance

SUSA is a Windows-based digital-forensics and incident-response workstation supported by practical documentation. It brings focused collection, examination and analysis utilities into one learning environment so an analyst can move from an investigation question to a reviewable result.

Important boundary SUSA does not replace organisational procedures, legal authority, validated forensic processes or experienced judgement. Confirm the scope, tool version and expected output before relying on a workflow in a real investigation.
02

Responsible use

Protect source evidence, work only within authority, and preserve enough context for another analyst to review the result.

Use an authorised environmentTreat recovered files, links, archives, memory images and suspicious samples as potentially sensitive or unsafe.
03

Ownership

Understand who owns the original work and how the project records its development.

Original SUSA material Copyright © 2024–2026 Joseph Jee

The original SUSA documentation, text, diagrams, artwork, project identity and source materials were independently created and are owned by Joseph Jee, except where third-party material is identified.

Development record The project's dated Git history, source files and published releases record its development. Repository-level terms take precedence where they provide more specific notice.
04

Documentation licence

Original SUSA documentation is available under clear non-commercial reuse conditions unless a page states otherwise.

Creative Commons licence Attribution-NonCommercial 4.0 International

You may share and adapt covered material for non-commercial purposes when all licence conditions are followed.

Read the CC BY-NC 4.0 licence
Permission is requiredfor uses outside those terms, including commercial use.
05

Project identity

Separate permission to reuse original documentation from rights in the SUSA identity and referenced products.

Licence boundarySUSA project identity The SUSA name, logo and other project-identity elements are not included in the documentation licence. Restriction They may not be used to imply ownership, affiliation or endorsement without prior written permission.
Third-party rightsRights remain with their owners Product names, trade marks, logos, screenshots, quoted text and other identified third-party material remain the property of their respective owners. Page-specific terms Where a page identifies different terms for particular material, those terms take precedence for that material.
06

Contact

Contact the project before using SUSA material outside the documentation licence.

Project contact Security Utility Suite for Analysts

For permission to use SUSA material outside the documentation licence, or for an ownership and licensing enquiry, contact the project by email.

Helpful details Include the material, intended use, audience, distribution method and whether the proposed use is commercial.
Email the SUSA project
Need clarification? Ask before reusing material when the ownership or licence boundary is unclear. Contact the project