Benchnotes turns your investigation notes, tool output, and evidence into a client-ready incident report in about thirty minutes. You investigate. You conclude. Benchnotes does the typing.
For DFIR consultants, small IR firms & MSPs · No card required
Forensic artifacts recovered from the affected workstation confirm that a QakBot loader was executed on 8 July at 14:22 local time.[n3] Network capture subsequently identified command-and-control traffic to an external address over port 443, beaconing at approximately sixty-second intervals.[n5] Analysis of domain event logs found no evidence of lateral movement beyond the initial host.
Tap or hover a highlighted line — every sentence in the draft is traceable to your own notes. Nothing ships that you didn't source and sign.
Works with the output of the tools you already run
Benchnotes sits at the end of the investigation, not in the middle of it. Keep your tools, your process, and your judgment.
Bench notes, Volatility output, KAPE exports, timeline CSVs, EDR screenshots, PCAP observations, IOCs. Paste it or upload it — free intel enrichment runs automatically on every hash and indicator.
Executive summary, technical narrative, IOC tables, MITRE ATT&CK mapping, timeline, recommendations, appendices — in your branded template. Your notes are ground truth; the draft narrates what you found.
Every drafted sentence stays highlighted and source-linked until you approve it. Edit where you'd phrase it differently, sign off, export to DOCX or PDF.
Every AI-drafted sentence is mapped to the note or artifact it came from, and the full generation history is exportable. Better documentation of your process than the Word doc you're writing today.
Bring your firm's DOCX template and section structure; Benchnotes fills it. No template yet? Start from a clean default modeled on standard IR report structure.
Encrypted at rest, never used for training, never shared with intel vendors. Cancel anytime and export every case as portable JSON.
Hashes and indicators you drop in are enriched against VirusTotal, MalwareBazaar, and abuse.ch feeds — cited in the draft, ready for the IOC appendix.
Techniques referenced in your notes map to MITRE ATT&CK automatically, and timestamped observations assemble into the incident timeline.
On 8 July 2026, a phishing email delivered a malicious archive to , resulting in execution of a QakBot loader on a single workstation. The threat was contained within of detection. No evidence of lateral movement or data exfiltration was identified.
| TYPE | INDICATOR | SOURCE |
|---|---|---|
| SHA-256 | 9f2a…e41c | [n8] · VirusTotal 54/72 |
| C2 | 185.220.—.—:443 | [n5] · PCAP |
| File | invoice_7841.zip | [n2] · Mail gateway |
Rendered into your DOCX template on export — headers, footers, numbering and all.
Benchnotes will not tell your client what happened — you will. It drafts the document you would have written, from the findings you recorded. Nothing reaches the export you didn't approve.
Drafted sentences without a source in your workspace are flagged, not hidden. The review view exists so that hallucination is a visible, fixable state — never a surprise in a shipped report.
Benchnotes is built for client and insurer incident summaries — the reports you write every week. It is not positioned for formal examination reports or expert-witness work, and it won't pretend to be.
You close the investigation Tuesday night and spend three hours Wednesday assembling the deliverable — same structure as the last five reports, rewritten from scratch anyway.
5 reports/mo × 2 hrs saved × your billable rate
= pays for itself in the first case
After every BEC cleanup, ransomware scare, or malware removal, the client wants a document explaining what happened and what you did. Benchnotes turns ticket notes and tool output into that document — branded and done before the invoice goes out.
The incident writeup becomes a deliverable
you attach to every engagement
The draft is generated only from what's in your case workspace — your notes are ground truth. Every sentence stays highlighted and source-linked until you approve it, and unsourced sentences are flagged. Nothing ships unsigned.
Yes. Bring your branded DOCX template and section structure; Benchnotes fills it. If you don't have one, you get a clean default modeled on standard IR report structure.
Cases are yours. Encrypted at rest, never used to train models, never shared with third-party threat-intel vendors. If you cancel, every case exports as portable JSON. Beta users get a straight answer on architecture during onboarding — ask me anything.
At launch you can paste or upload output from any tool — sandbox reports included. Direct API connectors (ANY.RUN, Joe Sandbox, Triage) are next on the roadmap once the core report engine is solid with beta users.
Plans start at $149/month per analyst with unlimited cases and reports. Founding beta users get a rate of $49/month for six months in exchange for honest feedback.
Founding users get $49/month for six months, a direct line to the builder, and a product shaped around their actual reports.
I'm a solo developer with a decade of shipping B2B software. I'm building Benchnotes because every IR practitioner I know complains about the same three hours on Wednesday morning — the write-up, after the real work is done. I'm not raising money, I'm not chasing enterprise contracts, and I answer my own email. If Benchnotes doesn't save you real time in your first two cases, tell me and I'll fix it — or refund you.
I reply to every request personally, usually same day. No spam, no list-selling.
✓ Request received. I'll reply personally within 24 hours.