Back to updates
New releaseJul 26, 2026

Crow-Eye v0.12.5

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with AI-assisted analysis and court-grade evidence sealing.

Share

Crow-Eye — Windows Forensics Engine

Crow-Eye Logo

A forensic time machine for Windows.
Crow-Eye doesn't just detect — it reconstructs what actually happened on the timeline, from acquisition all the way to a verdict traceable to its source records.

License: GPL v3 Version Correlation Engine Platform Python Discord GitHub stars GitHub issues Last commit

Table of Contents

Overview

Crow-Eye is an open-source (GPL-3.0) Windows forensics engine that unifies acquisition, analysis, verification, intelligence, and AI. Most security tools ask "is this bad?" and clear whatever looks legitimate. Crow-Eye asks a different question: "what happened?" It correlates all activity — suspicious or not — and reconstructs the actual sequence of events on a system, so the truth of an investigation is rebuilt from evidence rather than guessed from alerts.

That reconstruction-first design is exactly what it takes to hunt APT and nation-state threats: sophisticated adversaries live inside legitimate tools (powershell.exe, PsExec, certutil) and in the sequence of actions — invisible to tools that clear anything that looks normal. Because Crow-Eye never clears anything and reasons over execution artifacts (which survive log tampering and anti-forensics), the attack can't hide. The same engine stays approachable for everyday DFIR work and for non-experts who simply want to know what happened on a computer.

  • 🕰️ Reconstruct, don't just detect — rebuild the timeline of what actually occurred.
  • 🖥️ Cross-platform — full live + offline analysis on Windows; offline analysis and forensic-image parsing on Linux (live parsers are Windows-only).
  • 🔒 Private by design — 0 ms of data sent off-device; the Eye AI assistant can run fully air-gapped.
  • 🧾 Court-grade — evidence is cryptographically sealed and every step is auditable.
  • 📦 Current version: 0.13.0 · Correlation Engine: 1.7.0 · License: GPL-3.0.

✨ Highlights

  • Reconstruction over detection. Correlates every artifact into one navigable, per-entity story instead of a pile of alerts.
  • Integrated end to end — acquisition → correlation → timeline → behavioral analytics → AI → sealed case memory: a full pipeline no single incumbent tool spans.
  • Artifact-deep, not log-shallow. Prefetch, Amcache, ShimCache, SRUM, MFT, USN, LNK/JumpLists and more survive the log clearing and "living-off-the-land" tricks that blind log-only tools.
  • The Eye AI assistant — natural-language forensic investigation with an auditable, tamper-evident chain of custody, runnable in the cloud, on a private server, or fully offline.
  • User Behavior Analytics (UBA) — turns raw artifacts into a plain-English, HR/examiner-readable activity story.
  • Free & open-source (GPL-3.0) — auditable by anyone, with an active research and documentation effort.

👥 Who Crow-Eye Is For

Crow-Eye is used across very different workflows. Each one enters the engine through a different door:

You areYour typical inputWhere to start
Corporate IR / MSSP / MDRTargeted collections from Velociraptor, KAPE, or EDR-native collectionOffline Importer → Correlation Engine → UBA
Law enforcement / forensic labsFull forensic images (E01, VHDX, VMDK, Raw) with chain-of-custody requirementsImage analysis → Correlation Engine → Narrative Map
Internal security / insider-threat & HR investigationsLive systems or collected artifactsLive analysis → UBA activity story
Students, educators & researchersSample images and lab dataEye-Describe → Quick Start

Any collector works. Crow-Eye does not require its own acquisition tool. Point the Offline Importer at a folder of raw artifacts produced by Velociraptor, KAPE, an EDR collection package, or any other collector — it indexes the supported artifacts and runs the offline parsers over them. Separately, output from Plaso, Autopsy, Volatility or any other tool can be brought in as CSV, JSON, or SQLite via Import Evidence and correlated alongside native artifacts.

🧭 Subsystems at a Glance

Crow-Eye is built as an integrated loop — each stage feeds the next, from raw disk to a defensible verdict.

Categories