Self-hosted · case-centric · AI optional
Carry an investigation from collected evidence to defensible reporting
CaseScope organizes evidence, tool output, searches, analyst decisions, findings, and reporting in one case-centric workspace—without forcing your evidence into a cloud service.
Turn collected evidence into a structured, reviewable investigation—and carry analyst decisions through to the final report.
Self-hosted · Mixed evidence sources · Analyst-controlled findings · AI optional
The investigation is larger than any one tool
Free tools can answer individual questions. They do not automatically keep the investigation around those answers.
Fragmented work
- Collection in KAPE or Velociraptor
- Events in Hayabusa or a viewer
- Memory in Volatility
- PCAP in Zeek or Wireshark
- Narrative rebuilt in notes and spreadsheets
What CaseScope carries
Three operational outcomes
Preserve investigative context
Keep evidence, processing history, searches, notes, decisions, and findings attached to the case.
Reduce manual handoffs
Move results between processing, review, hunting, and reporting without rebuilding context in spreadsheets.
Produce reviewable work
Show what was processed, what the analyst concluded, and how the reported finding was supported.
Demonstration case NW-IR-041
Same organization, case number, analyst, host, user, timestamps, and findings everywhere on this site. These frames are synthetic UI until captures from CaseScope 4.26.13 replace them. Read the full demo narrative.
Why pay instead of assembling free tools
The claim is less glue, less reconstruction, more consistent case work—not replacement of every forensic utility.
| Free individual tools | CaseScope |
|---|---|
| Excellent at specific artifact or processing tasks | Connects those tasks to a persistent investigation |
| Output often lives in separate files and formats | Keeps processing results and analyst work with the case |
| Analyst reconstructs context between tools | Carries context across evidence, review, findings, and reporting |
| Documentation depends on individual habits | Provides a consistent place to record decisions and support |
| Repeating work can require manual reconstruction | Preserves processing and investigative history |
| Usually acquired and supported independently | Provides a supported product workflow and accountable release path |
Evidence snapshot
Compatibility is status-qualified. A parser path is not a certified vendor integration.
Deployment and AI
Use CaseScope without AI, with a locally hosted model, or with an approved external provider. Core investigation workflows do not depend on AI.
Self-hosted
Evidence stays in your environment. Nothing leaves by default.
AI off, local, or external
Deployment choices, not product editions.
Licensing metadata only
Check-ins are for entitlement and host binding, not case evidence. Trust page
Buyer paths
Internal IR
One workspace after collection so the team is not stitching tools during the incident.
Incident responseMSP / consulting
Intake a client collection, process supported artifacts, record decisions, export a consistent package.
MSP pageStart with a controlled evaluation
Evaluation is for product assessment with synthetic, demonstration, or expressly approved data. A live matter needs an Incident, paid pilot, Annual, or MSP license.