← All Netgraph solutions
Forensics & Incident ResponseIntelligence & Operations

Evidence that holds up. Clocks that never slip.

Netgraph treats an incident the way a regulator will: every artifact lands in a tamper-resistant vault with hash-chained chain-of-custody, every statutory clock — CERT-In's 6 hours, DPDP's 72 — is tracked live, and every forensic fact is a graph node with provenance. The investigation is a traversal; the evidence pack builds itself as you work.

Hash-chained custodyCERT-In 6hDPDP 72h clocksPICERL auto-progressEndpoint live responsePCAP / IDS / flow analysisRegulator-ready exports

What ships in the module

First alert to final report, on one evidence chain.

01

Artifact Vault

Tamper-resistant evidence storage with hash-chained chain-of-custody — every access and every transfer is recorded in the chain, and exports arrive regulator-ready.

02

Explore / Scope / Investigate

Three forensics consoles for working an incident end to end — explore what happened, scope how far it reached, investigate it down to the full timeline from the first alert.

03

Statutory breach clocks

The Declared Incident / Breach module runs the clocks that matter — CERT-In 6-hour, DPDP 72-hour, GDPR and HIPAA — tracked live and surfaced on the CISO scorecard, not on a sticky note.

04

PICERL checklists

SANS PICERL incident checklists auto-progress as agent investigations write back — and human edits are preserved. The checklist stays current without an analyst babysitting it.

05

Case-centric IR

Semantic timeline, evidence attachments with tags, audit-trail-to-comments and on-call assignment — the case is the single working surface for the whole response.

06

Endpoint forensics

Process-tree analysis, live response and quarantine artifacts pulled from the fleet — the endpoint side of the investigation happens in the same console as everything else.

07

Network evidence

PCAP, IDS and flow forensic analysis for the network leg of the case — packet-level truth when logs alone won't settle the question.

08

Graph-native provenance

Every forensic fact is a graph node with provenance. The investigation is a traversal across them — and because provenance is intrinsic, the evidence pack is constructive, not reconstructive.

09

Regulator-ready exports

Chain-of-custody ledgers and evidence packs export in a form built for submission — what you hand the regulator is what the vault recorded, hash chain intact.

Chain of custody, by construction

Every touch of the evidence is in the chain.

Each artifact in the vault carries a hash-chained custody ledger: who collected it, who accessed it, where it was transferred — every entry linked to the last, so tampering breaks the chain visibly. When the declared-incident clock is running, the same ledger is what you submit.

  • Accesses and transfers append to the chain — nothing is edited in place, ever.
  • Statutory clocks run live against the declaration time — CERT-In 6h, DPDP 72h, GDPR, HIPAA.
  • PICERL phases advance automatically as investigation findings write back to the case.
  • Exports carry the full chain — regulator-ready without a re-assembly weekend.

Functionality map

Module functions at a glance

FunctionWhat it doesWhere it lives
Artifact VaultTamper-resistant evidence storage with hash-chained custody and regulator-ready exportsForensics ▸ Artifact Vault
Chain of CustodyAppend-only ledger of every access and transfer per artifactForensics ▸ Chain of Custody
Explore / Scope / InvestigateWork an incident from first alert to full timelineForensics ▸ Explore / Scope / Investigate
Declared IncidentStatutory clocks — CERT-In 6h, DPDP 72h, GDPR, HIPAA — tracked live, on the CISO scorecardForensics ▸ Declared Incident
PICERL checklistsSANS phases auto-progress on agent write-back; human edits preservedCase view
Case-centric IRSemantic timeline, tagged evidence attachments, audit-to-comments, on-call assignmentCase management
Endpoint forensicsProcess trees, live response, quarantine artifacts from the fleetFleet / endpoint consoles
Network forensicsPCAP / IDS / flow analysis for network evidenceNDR forensics

See it live

Run your next tabletop on it. Watch the evidence pack build itself.