Community Edition out now on GitHub
Atlas runs the investigation. You handle the incident.
What takes fifteen hours by hand, Atlas covers in about three. It works from the disk images and logs you already have, runs the tools examiners trust, and answers the questions you actually ask. Every finding links back to the evidence behind it.
Built for IT teams, their service providers and DFIR teams who need a solid first picture of an incident fast. Not another viewer. A case-driven workflow that ends in a report you can hand over.
- Automated artifact extraction
- Questions in, findings out
- Knowledge that carries over
Runs the tools you already trust: Hayabusa, Eric Zimmerman’s suite, and your own Python plugins.
Why Atlas
The first pass is the long part, not the hard part.
Two encrypted disk images, a file server and a domain controller, plus the firewall logs. Extracting the artifacts, running the parsers, lining up the timelines: none of it is hard, and on a case that size it runs to roughly fifteen hours before anyone answers the first real question. Atlas covers that groundwork in about three hours and hands over findings with their evidence attached, so your hours go into judgement rather than preparation.
- up to92%
- of the findings the manual analysis produced, reached in about three hours
- 3h
- to a first technical picture. Runtime scales with the evidence.
- 15h
- our team average for the same case by hand
- 5×
- faster on the first pass
Measured on one internal test case: two encrypted VMDK images, a file server and a domain controller, plus firewall logs. The fifteen hours is what our team averages on a case that size by hand. Runtime and results shift with the volume of evidence, the questions you ask and the model you connect, so treat these as one reference point, not a promise.
When leadership wants answers today
Ransomware at six in the evening. The board wants a picture by the morning meeting, and the external lab has a two-week queue. Load the evidence into Atlas, ask your questions, and review the findings over breakfast.
Reference case: two encrypted VMDK images (file server, domain controller) and firewall logs
By hand
With Atlas
In Germany, commercial IT forensics commonly bills 150 to 250 € an hour, so fifteen hours land between 2,250 and 3,750 €. Atlas stays at roughly 15 $ in tokens.
-
01
Your question. All the evidence.
Point Atlas at the whole case, not one host at a time. It works through images and logs together and connects what it finds across systems.
-
02
Runs while you don’t.
Start the analysis in the evening. Extraction and tool runs keep going overnight, and you start the morning with findings instead of a progress bar.
-
03
Escalate with a real handover.
Atlas does not replace your forensic specialist. It gives them, and your IT team, a structured and evidence-backed starting point instead of a raw disk.
Reference comparison, not a guarantee. Time and cost depend on the evidence, the depth and the model. Atlas supports the examiner; it does not sign the report.
The product
Findings you can review. Not a data dump.
Every tool call, in order. Each finding links to the step that produced it and to the artifacts behind it, so the investigation stays reviewable.
The report: findings, evidence and a timeline in one document. Markdown or PDF, ready to review and hand over.
Capabilities
What Atlas actually does
The Brain
Every case makes the next one faster.
Most tools forget everything when the case closes. Atlas keeps the lessons: which tool call worked, which path led nowhere, what a certain artifact usually means. It writes them down as Brain Injections, generalised and anonymised, and reads them back next time.
-
Brain Injections
Lessons from running and finished analyses, stored in generalised form. No case data, no client names.
-
It writes itself
If one RECmd flag beats another, that goes into the Brain. Nobody has to remember to document it.
-
You stay in control
Open it, read it, edit it. The Brain is a living wiki, not a black box.
How it works
From evidence to report in six steps
-
01
Evidence
Give Atlas what the case produced: disk images, logs, exports. Acquisition stays with you.
-
02
Question
Ask what you need to know. “What happened on this host?” “Any suspicious RDP sessions?” “Is there data exfiltration?”
-
03
Extract
Atlas pulls the relevant artifacts and runs the right tools on them, Hayabusa, RECmd and others, based on the evidence and your question.
-
04
Findings
For each question: an answer, a confidence score, the observations that matter and the artifacts that back them. Correlated across hosts.
-
05
Report
A structured technical report with timeline, in Markdown or PDF. Review it, annotate it, hand it over.
-
06
Brain
What worked goes into the Brain, generalised and anonymised, so the next run starts smarter.
Licensing
Two ways to use Atlas.
Community Edition
FreeFor private use and evaluation. Run Atlas on your own cases, test it in your lab, and it stays free for private use.
- Private, non-commercial use
- Evaluation in your organisation, up to 31 days
- The full workflow with your own LLM
Professional
LicenceFor labs, incident-response teams and service providers using Atlas commercially, in their environment and their workflow.
- Commercial and professional use
- Runs in your own infrastructure
- Terms and evaluation on request
The Community Edition is on GitHub. Clone it, start the dashboard and click through the bundled example investigations — no evidence and no API key needed for a first look.
Contact
Let’s talk about your incident workflow
Evaluate Atlas, ask about a licence, or tell us how you handle incidents today. Use the form or write to contact@dfir-systems.de.
For business and professional enquiries.
FAQ
Questions people ask
What is Atlas?
A DFIR tool for the first technical assessment of a security incident. It extracts artifacts from your evidence, runs established tools, answers the questions you define, correlates findings across systems and writes a technical report. An LLM is one component of it, not the product.
Who is it for?
IT teams, their IT service providers, DFIR and incident-response teams, security labs and anyone who has to make sense of forensic evidence under time pressure.
When can I get it?
It is out. The Community Edition is on GitHub. Clone the repository, run the installer, and the dashboard opens with finished example investigations you can click through right away.
Is Atlas free?
For private use and evaluation, yes. Private use falls under the PolyForm Noncommercial licence, evaluation in your organisation for up to 31 days under the PolyForm Free Trial licence. Beyond that, commercial and professional use needs a licence from us. Donations are welcome but never required.
Can I use my own LLM?
Yes. Atlas talks to any OpenAI-compatible backend — a cloud provider, a gateway or a model on your own hardware. Nothing is preselected, and the repository documents the setups.
How do I get a commercial licence?
Use the contact form or write to contact@dfir-systems.de.
What is the Brain?
The knowledge layer of Atlas. From running and finished analyses it writes down what worked, generalised and anonymised, and uses it in the next run. You can read, edit and tune every entry.
Does Atlas replace a forensic analyst?
No. Atlas does the first pass: extraction, tool runs, correlation, a technical report. The examiner reviews, interprets and decides what goes into the case. The comparison is about time and cost for that first pass, not about replacing anyone.
Like Atlas? The Community Edition stays free, and donations keep the work going. Support Atlas