
Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with AI-assisted analysis and court-grade evidence sealing.
A forensic time machine for Windows.
Crow-Eye doesn't just detect — it reconstructs what actually happened on the timeline, from acquisition all the way to a verdict traceable to its source records.
Crow-Eye is an open-source (GPL-3.0) Windows forensics engine that unifies acquisition, analysis, verification, intelligence, and AI. Most security tools ask "is this bad?" and clear whatever looks legitimate. Crow-Eye asks a different question: "what happened?" It correlates all activity — suspicious or not — and reconstructs the actual sequence of events on a system, so the truth of an investigation is rebuilt from evidence rather than guessed from alerts.
That reconstruction-first design is exactly what it takes to hunt APT and nation-state threats: sophisticated adversaries live inside legitimate tools (powershell.exe, PsExec, certutil) and in the sequence of actions — invisible to tools that clear anything that looks normal. Because Crow-Eye never clears anything and reasons over execution artifacts (which survive log tampering and anti-forensics), the attack can't hide. The same engine stays approachable for everyday DFIR work and for non-experts who simply want to know what happened on a computer.
Crow-Eye is used across very different workflows. Each one enters the engine through a different door:
| You are | Your typical input | Where to start |
|---|---|---|
| Corporate IR / MSSP / MDR | Targeted collections from Velociraptor, KAPE, or EDR-native collection | Offline Importer → Correlation Engine → UBA |
| Law enforcement / forensic labs | Full forensic images (E01, VHDX, VMDK, Raw) with chain-of-custody requirements | Image analysis → Correlation Engine → Narrative Map |
| Internal security / insider-threat & HR investigations | Live systems or collected artifacts | Live analysis → UBA activity story |
| Students, educators & researchers | Sample images and lab data | Eye-Describe → Quick Start |
Any collector works. Crow-Eye does not require its own acquisition tool. Point the Offline Importer at a folder of raw artifacts produced by Velociraptor, KAPE, an EDR collection package, or any other collector — it indexes the supported artifacts and runs the offline parsers over them. Separately, output from Plaso, Autopsy, Volatility or any other tool can be brought in as CSV, JSON, or SQLite via Import Evidence and correlated alongside native artifacts.
Crow-Eye is built as an integrated loop — each stage feeds the next, from raw disk to a defensible verdict.