Palimpsest: AI-Augmented Digital Forensics & Incident Response
Palimpsest is an on-premise AI forensic analysis system that helps DFIR teams process digital evidence faster, reconstruct attack timelines, preserve chain of custody, and produce analyst-reviewed investigation reports.
Built for sensitive evidence environments, Palimpsest uses local AI to support forensic triage, artifact classification, timeline reconstruction, MITRE ATT&CK mapping, and defensible reporting.
Every erasure leaves a shadow.
What Is Palimpsest?
Local AI for Digital Forensics Teams
Palimpsest helps cybersecurity and forensic teams investigate incidents faster without sending sensitive evidence to external cloud AI tools.
It is designed to support the full digital forensic investigation process, from raw evidence intake to analyst-reviewed reporting. Instead of replacing forensic analysts, Palimpsest helps them review more evidence, identify stronger leads, connect events across sources, and explain findings clearly.
The Problem
Digital Evidence Is Growing Faster Than Teams Can Review It
Modern breaches create massive amounts of evidence. Logs, disk images, memory captures, PCAPs, endpoint telemetry, mobile artifacts, and cloud records all need to be preserved, analyzed, correlated, and explained.
Manual review can slow investigations, delay response, and leave important evidence buried. Palimpsest helps teams move faster by using local AI to prioritize artifacts, identify patterns, and organize evidence into a clear investigation workflow.
The Solution
AI-Assisted Forensic Analysis Without Losing Evidence Control
Palimpsest applies on-prem AI to real forensic workflows. It helps analysts classify evidence, reconstruct timelines, map attacker behavior, and generate reports while keeping sensitive data inside the investigative environment.
This makes Palimpsest especially useful for organizations that handle confidential client data, regulated records, legal matters, incident response evidence, or internal security investigations.

Who Palimpsest Is Built For
Built for Teams Handling Sensitive Digital Evidence
MSSPs
Add AI-assisted digital forensics to managed security services, incident response retainers, and client-facing investigation reports.
Incident Response Teams
Accelerate breach investigation, evidence triage, root-cause analysis, timeline reconstruction, and post-incident reporting.
Legal and Litigation Support Teams
Support legal-hold workflows, expert review, evidence documentation, audit trails, and defensible reporting.
Healthcare, Finance, and Regulated Organizations
Analyze sensitive digital evidence in controlled environments where privacy, compliance, and evidence handling matter.
Internal Security Teams
Investigate breaches, insider activity, endpoint compromise, suspicious behavior, and policy violations without moving evidence outside the organization.
Evidence Palimpsest Handles
From Raw Artifacts to Investigation Context
Palimpsest is designed to support common digital forensic evidence sources, including:
- Disk images
- Memory dumps
- PCAP files
- System and application logs
- Endpoint telemetry
- Mobile artifacts
- Cloud records
- IOC lists
- Case notes and investigation metadata
The goal is not just to collect more evidence. The goal is to preserve, classify, correlate, and explain the evidence that matters.

The Five-Stage Forensic AI Pipeline
From Evidence Intake to Analyst-Reviewed Report
Palimpsest follows a five-stage forensic AI pipeline: Ingest, Extract, Analyze, Reconstruct, and Report.

1. Ingest
Collect digital evidence from disk images, memory captures, PCAPs, logs, mobile devices, endpoint systems, and cloud sources.
2. Extract
Process evidence using forensic tools, artifact parsers, hash workflows, and structured extraction methods.
3. Analyze
Use AI-assisted classification, anomaly detection, retrieval-based analysis, and MITRE ATT&CK mapping to identify relevant evidence faster.
4. Reconstruct
Correlate events across sources, normalize timelines, detect gaps, and surface suspicious activity or signs of anti-forensic behavior.
5. Report
Generate investigation summaries, dashboards, artifact references, chain-of-custody records, IOC exports, and analyst-reviewed forensic reports.
Core Capabilities
Built for Real Digital Forensic Workloads
AI Evidence Classification
Ranks and prioritizes artifacts so analysts can focus on the most relevant evidence first.
Timeline Reconstruction
Correlates events across logs, disk artifacts, memory evidence, endpoint telemetry, and network activity.
MITRE ATT&CK Mapping
Maps evidence patterns to attacker tactics, techniques, and procedures.
Analyst-Reviewed Forensic Reporting
Creates citation-backed investigation narratives designed for human review, evidence traceability, and defensible reporting.
Air-Gap Ready Operation
Supports sensitive environments where evidence must stay local and cannot be sent to external AI services.
Executive Dashboard
Turns complex forensic findings into clear timelines, risk summaries, and investigation briefings for clients, executives, and legal teams.
Why On-Prem AI Matters
Sensitive Evidence Should Stay Under Your Control
Digital forensic investigations often involve confidential business data, regulated records, privileged information, employee data, intellectual property, or potential litigation evidence.
Palimpsest is designed around local AI processing, private search, controlled evidence handling, and chain-of-custody awareness. Instead of sending artifacts to external AI platforms, Palimpsest supports an on-premise workflow where evidence remains inside the investigative environment.
This helps teams maintain stronger control over privacy, auditability, and evidence integrity.

What Palimpsest Produces
Clear Outputs for Technical, Executive, and Legal Teams
Palimpsest turns complex forensic data into investigation-ready deliverables, including:
- Prioritized evidence lists
- Artifact relevance scoring
- Incident timelines
- MITRE ATT&CK mapping
- Executive risk summaries
- Analyst-reviewed forensic reports
- Chain-of-custody records
- IOC exports
- SIEM handoff packages
- Litigation and regulatory support documentation
Each output is designed to help answer four key questions: what happened, when it happened, what evidence supports it, and what should happen next.
Why Goodin AI
Forensic Expertise. Cybersecurity Experience. AI-Powered Investigation.
Goodin AI combines digital forensic science, cybersecurity analysis, and AI-driven incident response to help teams investigate breaches faster and with greater confidence.
Palimpsest is built around a simple principle: AI should support forensic analysts, not replace them. Every workflow is designed to preserve evidence integrity, support analyst review, and produce clear, defensible outputs.
Engagement Models
Choose the Right Palimpsest Engagement
Sentinel
Monthly Retainer
Ongoing AI-augmented monitoring, anomaly detection, executive risk briefings, and priority incident response support.
Investigator
Per Engagement
A full forensic investigation using the five-stage Palimpsest pipeline, from evidence extraction to analyst-reviewed reporting.
Expert
Litigation Support
Expert witness, legal-hold, regulatory response, audit trail, and trial-support services for high-stakes digital evidence matters.
See Palimpsest in Action
Schedule a live demonstration and see how Palimpsest turns raw digital evidence into a clear forensic investigation workflow, from evidence intake to timeline reconstruction and analyst-reviewed reporting.
Built for DFIR teams, MSSPs, legal support, regulated organizations, and sensitive evidence environments.

