Kanvas for Incident Response
KANVAS is a DF/IR case management tool inspired by the infamous Spreadsheet of Doom (SOD). Built with PySide6 (PyQt), it runs entirely on your machine, no web server, no setup, no infrastructure. Just download, launch and get to work.
One-click report generation using Kanvas
Timeline, Lateral Movement, Diamond Model, Investigation summary, etc.
Incident Timeline
Automatically build timelines from Excel, segmented by days.
Lateral Movement
Visualize threat atatcker connections and movement paths .
MITRE D3FEND Mapping
Correlate detections with D3FEND matrix for mitigation.
MITRE Flow Builder
Visualize and share sequences of adversary actions.
External Lookups
Threat intel,VirusTotal, Shoden, vulnerability checks, etc.
Quick references
Knowledge base for LOLBAS, Event IDs, DDL sideloading, etc