Evidence that holds up. Clocks that never slip.
Netgraph treats an incident the way a regulator will: every artifact lands in a tamper-resistant vault with hash-chained chain-of-custody, every statutory clock — CERT-In's 6 hours, DPDP's 72 — is tracked live, and every forensic fact is a graph node with provenance. The investigation is a traversal; the evidence pack builds itself as you work.
What ships in the module
First alert to final report, on one evidence chain.
Chain of custody, by construction
Every touch of the evidence is in the chain.
Each artifact in the vault carries a hash-chained custody ledger: who collected it, who accessed it, where it was transferred — every entry linked to the last, so tampering breaks the chain visibly. When the declared-incident clock is running, the same ledger is what you submit.
- Accesses and transfers append to the chain — nothing is edited in place, ever.
- Statutory clocks run live against the declaration time — CERT-In 6h, DPDP 72h, GDPR, HIPAA.
- PICERL phases advance automatically as investigation findings write back to the case.
- Exports carry the full chain — regulator-ready without a re-assembly weekend.
Functionality map
Module functions at a glance
| Function | What it does | Where it lives |
|---|---|---|
| Artifact Vault | Tamper-resistant evidence storage with hash-chained custody and regulator-ready exports | Forensics ▸ Artifact Vault |
| Chain of Custody | Append-only ledger of every access and transfer per artifact | Forensics ▸ Chain of Custody |
| Explore / Scope / Investigate | Work an incident from first alert to full timeline | Forensics ▸ Explore / Scope / Investigate |
| Declared Incident | Statutory clocks — CERT-In 6h, DPDP 72h, GDPR, HIPAA — tracked live, on the CISO scorecard | Forensics ▸ Declared Incident |
| PICERL checklists | SANS phases auto-progress on agent write-back; human edits preserved | Case view |
| Case-centric IR | Semantic timeline, tagged evidence attachments, audit-to-comments, on-call assignment | Case management |
| Endpoint forensics | Process trees, live response, quarantine artifacts from the fleet | Fleet / endpoint consoles |
| Network forensics | PCAP / IDS / flow analysis for network evidence | NDR forensics |
See it live
Run your next tabletop on it. Watch the evidence pack build itself.
Works with everything on the graph
EDR / EPP
The fleet agent supplies the endpoint evidence — process trees, live response and quarantine artifacts feed the vault.
Explore→NDR
Packet, IDS and flow forensics give the network leg of the case its ground truth.
Explore→Compliance & Reporting
Statutory clocks and hash-chained evidence packs flow straight into regulator submissions and the CISO scorecard.
Explore→