Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
28 criteria
baselineWhat evidence sources does the platform support for acquisition — endpoint disk/memory imaging, cloud service logs (M365, Google Workspace, AWS CloudTrail), mobile devices, and network traffic — and which require a separate module or license?
baselineDescribe how forensic soundness and chain-of-custody are preserved end-to-end (cryptographic hashing at acquisition, access logging, tamper-evidence), and whether the platform's output has held up in legal proceedings, with a reference.
baselineWhat is the typical time to acquire and process a full endpoint image or memory capture at scale (dozens to hundreds of hosts simultaneously) during an active incident, versus a single-host lab scenario?
baselineDoes the platform support remote, agentless acquisition for distributed/remote workforces, or does it require physical access or a pre-installed agent — and what is the coverage gap for unmanaged or BYOD devices?
baselineDetail timeline-reconstruction capability — can the platform automatically correlate artifacts across multiple evidence sources (endpoint, cloud, network) into a single unified attack timeline, or does the analyst manually correlate separate tool outputs?
baselineWhat analysis capabilities are built in for common artifact types (registry, event logs, browser history, memory analysis for malware/rootkits) versus requiring export to a separate third-party analysis tool?
baselineExplain reporting output — can the platform generate a legally-defensible, court-ready report automatically, and what customization exists for different audiences (legal counsel, executive summary, technical appendix)?
baselineHow does the platform integrate with the broader incident response workflow (SOAR, case management, threat intel) so forensic findings feed back into containment and eradication decisions in real time rather than after the incident is closed?
baselineWhat is the pricing model — per case/investigation, per endpoint, or a flat enterprise tier — and what is the emergency/surge rate if a large-scale investigation requires acquiring evidence from many hosts simultaneously during an active incident?
baselineHow deep is forensic capability specifically for ephemeral cloud-native/container workloads (a compromised container that may no longer exist by the time investigation begins) versus traditional persistent endpoint/server forensics?
baselineCan the vendor provide real case studies or references where their forensic output was actually used in a legal proceeding (litigation, regulatory action, criminal prosecution) with a successful outcome, not just an aggregate case-count claim?
baselineWho within the organization can access forensic evidence and case data, and is there a strict, documented chain-of-custody-preserving access model given how sensitive and potentially legally consequential this evidence is?
baselineWhat data-residency and cross-border considerations apply to acquired evidence — can evidence be constrained to stay within a specific jurisdiction for legal/regulatory reasons, and how does the platform handle an investigation spanning multiple countries' data-protection regimes?
baselineDoes the platform support internal/employment-related investigations (HR-driven, not just external-attacker incidents) with an appropriately different workflow — legal/HR coordination, employee-privacy considerations — distinct from a technical breach investigation?
baselineWhat is the accuracy/false-positive rate on automated artifact interpretation (e.g., automatically flagging a registry key or log entry as malicious), and what is the process for a forensic analyst to correct an incorrect automated finding before it becomes part of a formal report?
baselineWhat training or certification support does the vendor provide for building up the customer's own internal forensics capability, as opposed to the customer being permanently dependent on the vendor's professional services for every investigation?
baselineProvide deep-dive incident investigations, including root cause analysis and forensic support, on an as-needed time-and-materials basis under pre-negotiated rates (Incident Response Support and Root Cause Analysis).
baselineProvide 24/7 cybersecurity threat and vulnerability monitoring with an expert team who can identify, isolate, and perform forensic analysis on possible impacts from attacks or vulnerabilities.
baselineSolution should be capable of assisting in finding log entries on originating systems for use in forensic investigations, and logs should be transmitted in encrypted format.
baselineThe Platform should (optionally) support integration of the EDR platform provided by the financial institution for endpoint threat hunting (process/service anomalies, hash values, connection anomalies), forensic artifact collection/matching against known IOCs, and quick response actions such as killing anomalous processes, deleting malicious binaries, and isolating endpoints.
baselineSecurity Incident and Crisis Management (one-time onboarding service): align the Security Incident management plan with the financial institution's Cyber Crisis Management Plan (CCMP) and Cyber Security Policy, develop a response plan/strategy prioritizing incidents by organizational impact, perform root cause analysis and recommend controls to prevent reoccurrence, and provide on-demand forensic analysis of logs.
baselineContinuous 24x7x365 monitoring is required for all alert severities, not just critical/high after business hours; the MSSP is expected to provide incident coordination, triage, investigation, root cause analysis, and remediation support (within defined authority boundaries) as part of SOC operations, with full forensic investigation/malware analysis available via the professional services block if requested.
baselineVendor must provide on-site support within eight (8) hours of request, primarily for incident response/DFIR activities, containment actions during active incidents, and critical technical support (not routine/non-incident-related support); the agency anticipates 6-12 onsite incidents annually with most response handled remotely.
baselineDeploy SIEM for in-scope infrastructure ensuring fully integrated, customized SIEM Security Analytics, MIS Dashboard, and Forensics functionality including incident forensics/session recreation and packet capture/network forensics; develop parsers for non-standard logs and write custom parsers for unsupported devices (35 custom parsers included, additional parsers billed separately).
baselineLog Management/Storage: logs available for live correlation/analysis online for 3 months and offline for 6 months; restoration of historical logs (at least 180 days) must be demonstrable at any time; historical log analysis must extend to a minimum of 5 years in the past; offline logs archived for regulatory/legal/audit/forensic use; BCP/DR planned with HA log collector in DC (primary site) and DR (secondary site, standby).
baselineSolution should integrate cloud-hosted platforms into the SIEM (event and network flow data) and perform deep packet forensics analysis on packets integrated from a packet analysis solution; provide connectors for the full device inventory in Annexure 1 with custom parser coding at no additional fee.
baselineProvide remote or deployable personnel for deep-dive incident investigations and root cause analysis on a time-and-materials basis, under pre-negotiated terms (On-Demand Forensic Support).
baselineCooperate fully with the organization in investigation of cybersecurity/privacy incidents, including participating in forensic and law enforcement investigations and notification of affected individuals/media/FCC as directed.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFIWhat evidence sources does the platform support for acquisition — endpoint disk/memory imaging, cloud service logs (M365, Google Workspace, AWS CloudTrail), mobile devices, and network traffic — and which require a separate module or license?Answer key — what a strong answer shows
Strong answers give a clear coverage matrix; a tool marketed as 'full forensics' that only covers endpoint disk imaging misses the majority of modern incident evidence sources.
RFPDescribe how forensic soundness and chain-of-custody are preserved end-to-end (cryptographic hashing at acquisition, access logging, tamper-evidence), and whether the platform's output has held up in legal proceedings, with a reference.Answer key — what a strong answer shows
Chain-of-custody and forensic soundness are the core requirement for evidence to be admissible; look for cryptographic verification at every handoff and, ideally, a real legal-proceeding reference.
RFIWhat is the typical time to acquire and process a full endpoint image or memory capture at scale (dozens to hundreds of hosts simultaneously) during an active incident, versus a single-host lab scenario?Answer key — what a strong answer shows
Look for a stated at-scale figure, since single-host demo timing is not representative of a real multi-host incident response scenario under time pressure.
RFIDoes the platform support remote, agentless acquisition for distributed/remote workforces, or does it require physical access or a pre-installed agent — and what is the coverage gap for unmanaged or BYOD devices?Answer key — what a strong answer shows
Remote/agentless acquisition is materially more useful for modern distributed workforces; the vendor should be candid about what's simply not reachable (e.g., unmanaged personal devices).
RFPDetail timeline-reconstruction capability — can the platform automatically correlate artifacts across multiple evidence sources (endpoint, cloud, network) into a single unified attack timeline, or does the analyst manually correlate separate tool outputs?
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Answer key — what a strong answer shows
Automated cross-source timeline correlation saves significant analyst time during an active incident; manual correlation across separate tool outputs is a common bottleneck this should solve.
RFIWhat analysis capabilities are built in for common artifact types (registry, event logs, browser history, memory analysis for malware/rootkits) versus requiring export to a separate third-party analysis tool?Answer key — what a strong answer shows
Look for genuinely built-in analysis for the most common artifact types; heavy reliance on export-to-third-party tooling adds friction and potential chain-of-custody gaps.
RFPExplain reporting output — can the platform generate a legally-defensible, court-ready report automatically, and what customization exists for different audiences (legal counsel, executive summary, technical appendix)?Answer key — what a strong answer shows
Strong answers describe distinct report formats for different audiences generated from the same underlying evidence, not a single raw technical dump requiring manual reformatting.
RFIHow does the platform integrate with the broader incident response workflow (SOAR, case management, threat intel) so forensic findings feed back into containment and eradication decisions in real time rather than after the incident is closed?Answer key — what a strong answer shows
Forensics that only produces a post-incident report misses the chance to inform active containment; look for real-time or near-real-time findings feeding the live IR process.
RFIWhat is the pricing model — per case/investigation, per endpoint, or a flat enterprise tier — and what is the emergency/surge rate if a large-scale investigation requires acquiring evidence from many hosts simultaneously during an active incident?Answer key — what a strong answer shows
Ask for specific emergency-scale pricing terms rather than assuming standard per-case rates apply during a genuinely large, time-critical investigation.
RFPHow deep is forensic capability specifically for ephemeral cloud-native/container workloads (a compromised container that may no longer exist by the time investigation begins) versus traditional persistent endpoint/server forensics?Answer key — what a strong answer shows
Container forensics is a genuinely harder problem given workload ephemerality — a vendor should give a specific answer on how evidence is captured before a container terminates, not just confirm general cloud-log support.
RFICan the vendor provide real case studies or references where their forensic output was actually used in a legal proceeding (litigation, regulatory action, criminal prosecution) with a successful outcome, not just an aggregate case-count claim?Answer key — what a strong answer shows
A specific, real legal-outcome reference is far more evaluable than a generic 'forensically sound' claim or an aggregate case-count — press for concrete detail.
RFPWho within the organization can access forensic evidence and case data, and is there a strict, documented chain-of-custody-preserving access model given how sensitive and potentially legally consequential this evidence is?Answer key — what a strong answer shows
Forensic evidence access control is itself part of chain-of-custody integrity — ask for a specific, strict access model, not just a general RBAC claim.
RFIWhat data-residency and cross-border considerations apply to acquired evidence — can evidence be constrained to stay within a specific jurisdiction for legal/regulatory reasons, and how does the platform handle an investigation spanning multiple countries' data-protection regimes?Answer key — what a strong answer shows
Cross-border evidence handling has real legal implications (data-protection law, evidentiary admissibility rules that vary by jurisdiction) — a vendor should have a specific answer, not treat this as the customer's problem alone.
RFIDoes the platform support internal/employment-related investigations (HR-driven, not just external-attacker incidents) with an appropriately different workflow — legal/HR coordination, employee-privacy considerations — distinct from a technical breach investigation?Answer key — what a strong answer shows
Internal investigations carry different legal and privacy considerations than external-attacker breach response — a vendor should clarify whether this is a genuinely supported, distinct workflow or an afterthought.
RFPWhat is the accuracy/false-positive rate on automated artifact interpretation (e.g., automatically flagging a registry key or log entry as malicious), and what is the process for a forensic analyst to correct an incorrect automated finding before it becomes part of a formal report?Answer key — what a strong answer shows
An incorrect automated finding that makes it into a legal/formal report has real consequences — ask for a real accuracy figure and a clear analyst-review/correction step before finalization.
RFIWhat training or certification support does the vendor provide for building up the customer's own internal forensics capability, as opposed to the customer being permanently dependent on the vendor's professional services for every investigation?Answer key — what a strong answer shows
A vendor genuinely interested in customer capability-building (not just recurring services revenue) should offer real training/certification support, not just sell professional-services hours indefinitely.
RFPProvide deep-dive incident investigations, including root cause analysis and forensic support, on an as-needed time-and-materials basis under pre-negotiated rates (Incident Response Support and Root Cause Analysis).
RFPProvide 24/7 cybersecurity threat and vulnerability monitoring with an expert team who can identify, isolate, and perform forensic analysis on possible impacts from attacks or vulnerabilities.
RFPSolution should be capable of assisting in finding log entries on originating systems for use in forensic investigations, and logs should be transmitted in encrypted format.
RFPThe Platform should (optionally) support integration of the EDR platform provided by the financial institution for endpoint threat hunting (process/service anomalies, hash values, connection anomalies), forensic artifact collection/matching against known IOCs, and quick response actions such as killing anomalous processes, deleting malicious binaries, and isolating endpoints.
RFPSecurity Incident and Crisis Management (one-time onboarding service): align the Security Incident management plan with the financial institution's Cyber Crisis Management Plan (CCMP) and Cyber Security Policy, develop a response plan/strategy prioritizing incidents by organizational impact, perform root cause analysis and recommend controls to prevent reoccurrence, and provide on-demand forensic analysis of logs.
RFPContinuous 24x7x365 monitoring is required for all alert severities, not just critical/high after business hours; the MSSP is expected to provide incident coordination, triage, investigation, root cause analysis, and remediation support (within defined authority boundaries) as part of SOC operations, with full forensic investigation/malware analysis available via the professional services block if requested.
RFPVendor must provide on-site support within eight (8) hours of request, primarily for incident response/DFIR activities, containment actions during active incidents, and critical technical support (not routine/non-incident-related support); the agency anticipates 6-12 onsite incidents annually with most response handled remotely.
RFPDeploy SIEM for in-scope infrastructure ensuring fully integrated, customized SIEM Security Analytics, MIS Dashboard, and Forensics functionality including incident forensics/session recreation and packet capture/network forensics; develop parsers for non-standard logs and write custom parsers for unsupported devices (35 custom parsers included, additional parsers billed separately).
RFPLog Management/Storage: logs available for live correlation/analysis online for 3 months and offline for 6 months; restoration of historical logs (at least 180 days) must be demonstrable at any time; historical log analysis must extend to a minimum of 5 years in the past; offline logs archived for regulatory/legal/audit/forensic use; BCP/DR planned with HA log collector in DC (primary site) and DR (secondary site, standby).
RFPSolution should integrate cloud-hosted platforms into the SIEM (event and network flow data) and perform deep packet forensics analysis on packets integrated from a packet analysis solution; provide connectors for the full device inventory in Annexure 1 with custom parser coding at no additional fee.
RFPProvide remote or deployable personnel for deep-dive incident investigations and root cause analysis on a time-and-materials basis, under pre-negotiated terms (On-Demand Forensic Support).
RFPCooperate fully with the organization in investigation of cybersecurity/privacy incidents, including participating in forensic and law enforcement investigations and notification of affected individuals/media/FCC as directed.