
Crow-Eye v0.12.7
Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with AI-assisted analysis and court-grade evidence sealing.
Crow-Eye — Windows Forensics Engine
A forensic time machine for Windows.
Crow-Eye doesn't just detect — it reconstructs what actually happened on the timeline, from acquisition all the way to a verdict traceable to its source records.
Table of Contents
- Overview
- ✨ Highlights
- 👥 Who Crow-Eye Is For
- 🧭 Subsystems at a Glance
- 🏗️ Architecture
- 📥 Download & Install
- 🚀 Quick Start
- 📂 Supported Artifacts
- 🔧 Analysis Modes
- 🧠 User Behavior Analytics (UBA)
- 🧩 Correlation Engine
- 👁️ Eye — The Forensics AI Assistant
- 📖 Eye-Describe — Byte-Level Artifact Knowledge Base
- 🧪 Quality & Validation
- 🔬 Research Platform
- 🛠️ Technical Notes
- 📸 Screenshots
- 🚧 Roadmap
- 📚 Documentation
- 🤝 Contributing
- 🌐 Website & Community
- 📄 License
- 📝 Citing Crow-Eye
- 💖 Support
- Credits
Overview
Crow-Eye is an open-source (GPL-3.0) Windows forensics engine that unifies acquisition, analysis, verification, intelligence, and AI. Most security tools ask "is this bad?" and clear whatever looks legitimate. Crow-Eye asks a different question: "what happened?" It correlates all activity — suspicious or not — and reconstructs the actual sequence of events on a system, so the truth of an investigation is rebuilt from evidence rather than guessed from alerts.
That reconstruction-first design is exactly what it takes to hunt APT and nation-state threats: sophisticated adversaries live inside legitimate tools (powershell.exe, PsExec, certutil) and in the sequence of actions — invisible to tools that clear anything that looks normal. Because Crow-Eye never clears anything and reasons over execution artifacts (which survive log tampering and anti-forensics), the attack can't hide. The same engine stays approachable for everyday DFIR work and for non-experts who simply want to know what happened on a computer.
- 🕰️ Reconstruct, don't just detect — rebuild the timeline of what actually occurred.
- 🖥️ Cross-platform — full live + offline analysis on Windows; offline analysis and forensic-image parsing on Linux (live parsers are Windows-only).
- 🔒 Private by design — 0 ms of data sent off-device; the Eye AI assistant can run fully air-gapped.
- 🧾 Court-grade — evidence is cryptographically sealed and every step is auditable.
- 📦 Current version: 0.13.0 · Correlation Engine: 1.7.0 · License: GPL-3.0.
✨ Highlights
- Reconstruction over detection. Correlates every artifact into one navigable, per-entity story instead of a pile of alerts.
- Integrated end to end — acquisition → correlation → timeline → behavioral analytics → AI → sealed case memory: a full pipeline no single incumbent tool spans.
- Artifact-deep, not log-shallow. Prefetch, Amcache, ShimCache, SRUM, MFT, USN, LNK/JumpLists and more survive the log clearing and "living-off-the-land" tricks that blind log-only tools.
- The Eye AI assistant — natural-language forensic investigation with an auditable, tamper-evident chain of custody, runnable in the cloud, on a private server, or fully offline.
- User Behavior Analytics (UBA) — turns raw artifacts into a plain-English, HR/examiner-readable activity story.
- Free & open-source (GPL-3.0) — auditable by anyone, with an active research and documentation effort.
👥 Who Crow-Eye Is For
Crow-Eye is used across very different workflows. Each one enters the engine through a different door:
| You are | Your typical input | Where to start |
|---|---|---|
| Corporate IR / MSSP / MDR | Targeted collections from Velociraptor, KAPE, or EDR-native collection | Offline Importer → Correlation Engine → UBA |
| Law enforcement / forensic labs | Full forensic images (E01, VHDX, VMDK, Raw) with chain-of-custody requirements | Image analysis → Correlation Engine → Narrative Map |
| Internal security / insider-threat & HR investigations | Live systems or collected artifacts | Live analysis → UBA activity story |
| Students, educators & researchers | Sample images and lab data | Eye-Describe → Quick Start |
Any collector works. Crow-Eye does not require its own acquisition tool. Point the Offline Importer at a folder of raw artifacts produced by Velociraptor, KAPE, an EDR collection package, or any other collector — it indexes the supported artifacts and runs the offline parsers over them. Separately, output from Plaso, Autopsy, Volatility or any other tool can be brought in as CSV, JSON, or SQLite via Import Evidence and correlated alongside native artifacts.
🧭 Subsystems at a Glance
Crow-Eye is built as an integrated loop — each stage feeds the next, from raw disk to a defensible verdict.