Palimpsest

Palimpsest: AI-Augmented Digital Forensics & Incident Response

Palimpsest is an on-premise AI forensic analysis system that helps DFIR teams process digital evidence faster, reconstruct attack timelines, preserve chain of custody, and produce analyst-reviewed investigation reports.

Built for sensitive evidence environments, Palimpsest uses local AI to support forensic triage, artifact classification, timeline reconstruction, MITRE ATT&CK mapping, and defensible reporting.

Every erasure leaves a shadow.

What Is Palimpsest?

Local AI for Digital Forensics Teams

Palimpsest helps cybersecurity and forensic teams investigate incidents faster without sending sensitive evidence to external cloud AI tools.

It is designed to support the full digital forensic investigation process, from raw evidence intake to analyst-reviewed reporting. Instead of replacing forensic analysts, Palimpsest helps them review more evidence, identify stronger leads, connect events across sources, and explain findings clearly.

The Problem

Digital Evidence Is Growing Faster Than Teams Can Review It

Modern breaches create massive amounts of evidence. Logs, disk images, memory captures, PCAPs, endpoint telemetry, mobile artifacts, and cloud records all need to be preserved, analyzed, correlated, and explained.

Manual review can slow investigations, delay response, and leave important evidence buried. Palimpsest helps teams move faster by using local AI to prioritize artifacts, identify patterns, and organize evidence into a clear investigation workflow.

The Solution

AI-Assisted Forensic Analysis Without Losing Evidence Control

Palimpsest applies on-prem AI to real forensic workflows. It helps analysts classify evidence, reconstruct timelines, map attacker behavior, and generate reports while keeping sensitive data inside the investigative environment.

This makes Palimpsest especially useful for organizations that handle confidential client data, regulated records, legal matters, incident response evidence, or internal security investigations.

Who Palimpsest Is Built For

Built for Teams Handling Sensitive Digital Evidence

MSSPs
Add AI-assisted digital forensics to managed security services, incident response retainers, and client-facing investigation reports.

Incident Response Teams
Accelerate breach investigation, evidence triage, root-cause analysis, timeline reconstruction, and post-incident reporting.

Legal and Litigation Support Teams
Support legal-hold workflows, expert review, evidence documentation, audit trails, and defensible reporting.

Healthcare, Finance, and Regulated Organizations
Analyze sensitive digital evidence in controlled environments where privacy, compliance, and evidence handling matter.

Internal Security Teams
Investigate breaches, insider activity, endpoint compromise, suspicious behavior, and policy violations without moving evidence outside the organization.

Evidence Palimpsest Handles

From Raw Artifacts to Investigation Context

Palimpsest is designed to support common digital forensic evidence sources, including:

  • Disk images
  • Memory dumps
  • PCAP files
  • System and application logs
  • Endpoint telemetry
  • Mobile artifacts
  • Cloud records
  • IOC lists
  • Case notes and investigation metadata

The goal is not just to collect more evidence. The goal is to preserve, classify, correlate, and explain the evidence that matters.

The Five-Stage Forensic AI Pipeline

From Evidence Intake to Analyst-Reviewed Report

Palimpsest follows a five-stage forensic AI pipeline: Ingest, Extract, Analyze, Reconstruct, and Report.

Core Capabilities

Built for Real Digital Forensic Workloads

AI Evidence Classification
Ranks and prioritizes artifacts so analysts can focus on the most relevant evidence first.

Timeline Reconstruction
Correlates events across logs, disk artifacts, memory evidence, endpoint telemetry, and network activity.

MITRE ATT&CK Mapping
Maps evidence patterns to attacker tactics, techniques, and procedures.

Analyst-Reviewed Forensic Reporting
Creates citation-backed investigation narratives designed for human review, evidence traceability, and defensible reporting.

Air-Gap Ready Operation
Supports sensitive environments where evidence must stay local and cannot be sent to external AI services.

Executive Dashboard
Turns complex forensic findings into clear timelines, risk summaries, and investigation briefings for clients, executives, and legal teams.

Why On-Prem AI Matters

Sensitive Evidence Should Stay Under Your Control

Digital forensic investigations often involve confidential business data, regulated records, privileged information, employee data, intellectual property, or potential litigation evidence.

Palimpsest is designed around local AI processing, private search, controlled evidence handling, and chain-of-custody awareness. Instead of sending artifacts to external AI platforms, Palimpsest supports an on-premise workflow where evidence remains inside the investigative environment.

This helps teams maintain stronger control over privacy, auditability, and evidence integrity.

What Palimpsest Produces

Clear Outputs for Technical, Executive, and Legal Teams

Palimpsest turns complex forensic data into investigation-ready deliverables, including:

  • Prioritized evidence lists
  • Artifact relevance scoring
  • Incident timelines
  • MITRE ATT&CK mapping
  • Executive risk summaries
  • Analyst-reviewed forensic reports
  • Chain-of-custody records
  • IOC exports
  • SIEM handoff packages
  • Litigation and regulatory support documentation

Each output is designed to help answer four key questions: what happened, when it happened, what evidence supports it, and what should happen next.

Why Goodin AI

Forensic Expertise. Cybersecurity Experience. AI-Powered Investigation.

Goodin AI combines digital forensic science, cybersecurity analysis, and AI-driven incident response to help teams investigate breaches faster and with greater confidence.

Palimpsest is built around a simple principle: AI should support forensic analysts, not replace them. Every workflow is designed to preserve evidence integrity, support analyst review, and produce clear, defensible outputs.

Engagement Models

Choose the Right Palimpsest Engagement

Monthly Retainer

Per Engagement

Litigation Support

See Palimpsest in Action

Schedule a live demonstration and see how Palimpsest turns raw digital evidence into a clear forensic investigation workflow, from evidence intake to timeline reconstruction and analyst-reviewed reporting.

Built for DFIR teams, MSSPs, legal support, regulated organizations, and sensitive evidence environments.