Account and process context
Inspect local users, suspicious processes, parent-child relationships, command lines, and service context.
Open Investigator · Windows host investigation
Open Investigator covers Windows server investigation scenarios where responders need account, process, network, persistence, service, file, and history evidence before deciding containment or remediation.
Search intent
Practical workflow
Inspect local users, suspicious processes, parent-child relationships, command lines, and service context.
Review listeners, connections, scheduled tasks, services, Run and RunOnce keys, WMI persistence indicators, and startup paths.
Use recent files and PowerShell history as investigation signals tied to evidence records.
Common searches
The source, usage examples, contribution notes, and issue tracker live in the public Open Investigator repository.