Forensic reference & case docs
Offline field companion for digital forensic examiners: artifact and file-signature references, vetted calculators, and encrypted case documentation. Private by design.
Built by a court-qualified forensic examiner: chain-of-custody and consent-to-search documentation you can complete, sign, and export at the scene — fully offline, encrypted on device, no account, no cloud.
Everything runs on-device. Look up an artifact location at a scene, convert a FILETIME value on a flight, or document a matter in a facility with no signal — the toolkit works the same everywhere.
DOCUMENTATION
• Evidence Forms — chain-of-custody and consent-to-search documentation with on-device signature capture. A completed form locks; corrections create a new version instead of overwriting the record.
• Case Workspace — organize matters, evidence items, and notes in an encrypted, on-device workspace.
• Exports — PDF and JSON generated locally, with a clear disclaimer. Deterministic: the same case produces the same bytes every time.
REFERENCE
• Artifact Reference — where forensic artifacts live across the operating systems you encounter in the field, with what each one does and does not establish.
• File Signature Database — identify files by their magic bytes; search by hex, extension, or type, with a hex quick-view.
• Calculators — timestamp (Unix epoch, FILETIME, WebKit, Cocoa, GPS), storage-size, hash, and base conversions, each validated against a published test-vector suite.
• Dashboard — resume recent work and pin the tools you use most.
BUILT FOR THE WITNESS STAND
DFIR Toolkit never touches your evidence. It does not acquire, image, parse, or analyze data, and it produces no findings or opinions — so nothing in it can be attacked as an unvalidated analytical tool, and nothing you do here can alter a working copy. It documents your process and answers your lookups; your validated tools and your judgment do the examination.
PRIVATE AND OFFLINE BY DESIGN
• No data collection — the app declares "Data Not Collected."
• No account, and no network connection required for any feature.
• Case data and captured signatures are encrypted at rest on your device.
• Full Dynamic Type and VoiceOver support; dark mode throughout.
FREE AND PRO
The reference side is free: the File Signature Database, all four calculators, the iOS artifact reference, and the Dashboard. DFIR Toolkit Pro unlocks the documentation side — Evidence Forms, Case Workspace, deterministic PDF and JSON exports, and the complete artifact library.
DFIR Toolkit Pro is an auto-renewable subscription: 1 year, $119.00 (USD). Payment is charged to your Apple Account at confirmation of purchase. The subscription renews automatically unless it is canceled at least 24 hours before the end of the current period. Manage or cancel anytime in your Apple Account settings.
Privacy Policy: https://thewaldrepcompany.com/privacy-policy/
Terms of Use (EULA): https://www.apple.com/legal/internet-services/itunes/dev/stdeula/
ABOUT
DFIR Toolkit is built by The Waldrep Company, an Alabama digital forensics practice. It was written by a working, court-qualified examiner to be the reference he wanted in the field: fast, offline, and defensible.
Questions, corrections, or an artifact we should add: thewaldrepcompany.com
Chrome-Stats does not own this Apple app. Please use these information below to contact the Apple app developer.