Self-hosted · case-centric · AI optional

Carry an investigation from collected evidence to defensible reporting

CaseScope organizes evidence, tool output, searches, analyst decisions, findings, and reporting in one case-centric workspace—without forcing your evidence into a cloud service.

Turn collected evidence into a structured, reviewable investigation—and carry analyst decisions through to the final report.

Self-hosted · Mixed evidence sources · Analyst-controlled findings · AI optional

The investigation is larger than any one tool

Free tools can answer individual questions. They do not automatically keep the investigation around those answers.

Fragmented work

  • Collection in KAPE or Velociraptor
  • Events in Hayabusa or a viewer
  • Memory in Volatility
  • PCAP in Zeek or Wireshark
  • Narrative rebuilt in notes and spreadsheets

What CaseScope carries

1
Evidence organization

Collections land in a case with timezone, analysts, and processing history.

2
Tool output and hunts

Supported artifacts become searchable without dropping case context.

3
Analyst decisions

Proposed indicators and findings are accepted or rejected by people.

4
Reporting

What was processed, what was concluded, and what supported it stay attached.

Three operational outcomes

Preserve investigative context

Keep evidence, processing history, searches, notes, decisions, and findings attached to the case.

Reduce manual handoffs

Move results between processing, review, hunting, and reporting without rebuilding context in spreadsheets.

Produce reviewable work

Show what was processed, what the analyst concluded, and how the reported finding was supported.

Demonstration case NW-IR-041

Same organization, case number, analyst, host, user, timestamps, and findings everywhere on this site. These frames are synthetic UI until captures from CaseScope 4.26.13 replace them. Read the full demo narrative.

Walk the seven-step tour · Read the sample report

Why pay instead of assembling free tools

The claim is less glue, less reconstruction, more consistent case work—not replacement of every forensic utility.

Free individual tools compared with CaseScope
Free individual toolsCaseScope
Excellent at specific artifact or processing tasksConnects those tasks to a persistent investigation
Output often lives in separate files and formatsKeeps processing results and analyst work with the case
Analyst reconstructs context between toolsCarries context across evidence, review, findings, and reporting
Documentation depends on individual habitsProvides a consistent place to record decisions and support
Repeating work can require manual reconstructionPreserves processing and investigative history
Usually acquired and supported independentlyProvides a supported product workflow and accountable release path

Evidence snapshot

Compatibility is status-qualified. A parser path is not a certified vendor integration.

Open the compatibility matrix

Deployment and AI

Use CaseScope without AI, with a locally hosted model, or with an approved external provider. Core investigation workflows do not depend on AI.

Self-hosted

Evidence stays in your environment. Nothing leaves by default.

AI off, local, or external

Deployment choices, not product editions.

Licensing metadata only

Check-ins are for entitlement and host binding, not case evidence. Trust page

Buyer paths

Internal IR

One workspace after collection so the team is not stitching tools during the incident.

Incident response

MSP / consulting

Intake a client collection, process supported artifacts, record decisions, export a consistent package.

MSP page

Education / lab

Approved noncommercial use with synthetic or expressly allowed lab data.

Education

Start with a controlled evaluation

Evaluation is for product assessment with synthetic, demonstration, or expressly approved data. A live matter needs an Incident, paid pilot, Annual, or MSP license.