The Ultimate Evidence Collector for Incident Responders and Forensic Investigators.


 Binalyze   TACTICAL   Datasheet


Binalyze TACTICAL is our standalone evidence collector for traditional DFIR situations.

Like all Binalyze products,TACTICAL is built on our proprietary IREC engine and offers the fastest and most comprehensive digital evidence collection on the market.

TACTICAL is available as a USB Dongle with a perpetual license. Looking for remote capabilities? Binalyze AIR has all the same evidence collection capabilities from a central management console.

Providing Cyber Resilience to World-class Enterprises Globally
logo-customers-pwc logo-customers-garmin logo-customers-sophos logo-customers-thy logo-customers-kpmg logo-customers-ey logo-customers-deloitte logo-customers-turkcell logo-customers-integrity360

Lightning Fast

Built on our proprietary IREC engine, acquiring digital forensic evidence is just a few clicks and is completed in under 10 minutes with TACTICAL.


150+ Evidence Types

Over 150 different types of system evidence and artifacts can be collected by TACTICAL.


Custom Evidence

In addition to the 150+ evidence types collected as standard, custom content profiles (path/pattern based) can be defined for specific evidence requirements.


Forensically Sound

TACTICAL's unique features ensure your acquired evidence is timestamped and ransomware shielded to maintain forensic integrity.


We collect more than 80 different types of system evidence in the following categories.

  • Disk Evidence

  • Memory Evidence

  • Browser Evidence

  • NTFS Evidence

  • Registry Evidence

  • Network Evidence

  • Event Logs Evidence

  • WMI Evidence

  • Process Execution Evidence

  • Miscellaneous Evidence

AIR Evidence List


We collect over 70 different system artifacts in the following categories.

  • Server Artifacts

  • Microsoft App Artifacts

  • Communications Artifacts

  • Social Artifacts

  • Productivity Artifacts

  • Utility Artifacts

  • Developer Tools Artifacts

  • Cloud Artifacts



In addition to the 150+ evidence types collected, custom content profiles (path/pattern based) can be defined for specific evidence requirements.