Platform  /  Tz0 Forensics

Module · digital investigation

Tz0 Forensics

Live forensics on the endpoint

The incident has already happened. Now somebody is going to ask what was taken, by whom and when — and the answer has to stand as evidence, not as suspicion.

Silent, remote collection · evidence kept on your own server

A trail of blocks leaving a workstation, with a magnifying glass over one of them

Chain of events

A single loose event proves nothing.

The value is not in the isolated record, it is in the order: what came before, what came after, and how much time separated the two. It is the reconstructed sequence that turns suspicion into an account that holds up outside the IT department.

tz0.yourcompany.local/forensics/search
Activity search in the Tz0 Forensics console: searching for the word payment returns 66 records with machine, person, program and window
Tz0 Forensics · web console

Console capture from an estate in production. Machine and person identification replaced; figures untouched.

What the module does

What happened on the machine, reconstructed.

It is the most sensitive module on the platform, and for that reason the one that demands the most process: use defined in policy, with scope and authorisation — not generic surveillance.

Live forensics

Installable tracking that records action on the endpoint: file changes, browsing, resource use and messenger conversations.

Session recording

Second-by-second video during use of financial, accounting or remote access tools, searchable by date, time, user or machine.

Reconstruction of what was deleted

Reconstructs a deleted file and identifies who changed, created or removed a folder.

Real-time alerting

Programmable warning during a fraud event, with screen capture, video and audio attached as evidence.

Evidence discovery

Scheduled analysis of file changes, browsing and conversations, with direct access or a report in the database.

Data recovery

Access to deleted files, e-mail and browsing history by reading disk sectors.

Password reverse engineering

Native reconstruction of passwords from over 300 mechanisms — browsers, FTP and e-mail clients — without brute force.

Evidence that holds up in proceedings

Collection preserved and exportable for use in legal proceedings or an internal investigation.

How it works

From suspicion to exportable evidence.

Every stage preserves the integrity of what was collected — the value of evidence lies in not having been contaminated along the way.

01 Authorise Case opened with scope and owner defined. 02 Collect The agent records on the endpoint, silently. 03 Preserve Evidence kept on the company’s own server. 04 Analyse Search by date, user machine or file. 05 Export Evidence package for the proceedings. Collection is defined by policy and by case. A module with this reach demands a written rule of use before it is switched on.

Console

The whole investigation in the browser.

Activity search screen in Tz0 Forensics: searching for the word payment returns 66 records with the device, person, program and window title for each
One word, and the trail surfaces. A search for “payment”: 66 records, each with the machine, the person, the program and the window title — here, “Microsoft Excel — Payments 2026”. The investigation starts from a term, not from a hunch about who to look at.
Thumbnail grid of a reconstructed session in Tz0 Forensics, each frame stamped with its capture time
The session, frame by frame. When the case calls for it, a machine’s timeline is reconstructed as thumbnails with a timestamp on every frame. They are deliberately unreadable here: what matters on this page is that the record exists and is dated, not what was on screen.
Deleted files screen in Tz0 Forensics, with 14,321 records and deletions broken down by program
What was deleted, and by which program. 14,321 deletion records in a day, grouped by program, with permanent deletion in a column of its own. Deleting stops being the end of the trail and becomes the start of it.
Network file activity screen in Tz0 Forensics, with creations, replacements, renames and deletions in shared folders
And what moved across the network. 79 operations in shared folders during the week — created, replaced, renamed, deleted — each with the machine, the person, the time and the path. What happens on the share stops being invisible.
Browser file activity screen in Tz0 Forensics, with 200 records spread across Chrome, Brave, Opera, Firefox and Edge
A download is a file, and a file leaves a trail. 200 file operations originating in the browser during the week, split across Chrome, Brave, Opera, Firefox and Edge. What came in over the web sits in the same record as everything else.

Screens from a real estate in production, not a demo environment. Anything identifying people, and customer names in network paths, was replaced with generic equivalents before publishing; the session thumbnails were deliberately left unreadable. Figures, percentages and the interface itself are untouched.

What changes in practice

Eight things that stop being one person’s word against another’s.

What was copied, changed or deleted is on the record.
A deleted file can be reconstructed.
A session in a financial system has video, not just a log.
The fraud alert arrives during the event, not afterwards.
Evidence comes out as a package that holds up in court.
The investigation does not depend on the machine sitting on the examiner’s desk.
Collection runs without alarming the person under investigation.
The scope of the investigation is documented from the moment it is opened.

Included with the module

Three tools in the same package.

A new report does not become a project. We do not build bespoke work for a single customer, but we look at every request: when the need serves everyone, the report goes into the product and reaches all customers in the next update.

Tz0 EIS

Report builder

Ships with the package, not sold separately. It is for people who want to build their own reports outside the browser.

Tz0 TNetX

Development platform

Carries agent communication across segmented topologies and lets the product be extended.

Tz0 Dashboard

Operations dashboard

The state of the estate on one screen, with whatever went off-target at the top. More than 600 ready-made reports, covering every module.

Who works this way

Investigation with evidence preserved.

“We built a security policy entirely on Tz0.”

Translated from Portuguese

Advanta
Corporate security policy

Chose Trauma Zer0 from thirteen players in the segment, after a proof of concept with five finalists.

TecBan
Banking terminal network

Before switching it on, define the rule. We help with both.

A 30-minute technical conversation: you describe the risk scenario, we point out what Forensics collects and what policy needs to exist first.