
Tool: The only ‘Kanvas’ you need when spreadsheets fail your IR case management
Source: YouTube · SANS Digital Forensics and Incident Response · published Dec 10, 2025 · 19:25
Gintto Anthony introduces Canvas, an open-source incident response documentation tool built on Python that uses Excel files as its core data store to prevent vendor lock-in 0:48.
Key Takeaways:
• Canvas wraps Excel files (SODS) with a QT-based UI for case management, lookups, and knowledge management without requiring web servers or databases 1:20
• Core design principles prioritize data portability, simple local setup, and ensuring data remains fully accessible without the tool 1:55
• Case management features include timeline visualization, lateral movement graphs, MITRE ATT&CK/D3FEND mapping, and STIX 2.0 export—all derived from the Excel file 4:30
• The lookups section integrates APIs for IP/domain/hash checks, Have I Been Pwned, CVE details, ransomware victim lists, and Microsoft App IDs for BEC investigations 7:35
• Version 0.4.4 adds MITRE Flow Builder, STIX 2.0 export, and LLM assistance with customizable profiles stored as YAML files 11:20
• Future roadmap includes multi-user support via Airtable/Supabase APIs, LLM-driven investigation workflows, and Velociraptor integration 11:45
Canvas provides investigators a portable, locally-run alternative to complex case management platforms, keeping data in familiar Excel formats while adding visualization and automation capabilities.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Incident Response. Commonly maps to: Security Operations, Security Assessment and Testing. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Our next speaker is actually a great another great contributor to the community. he has been involved in uh in multiple uh projects over the last uh few years and uh he's uh he's going to be sharing with us his latest and greatest research and I think uh once again um from in the previous talk we were have we had some tool to actually help us in the forensic acquisition process now we're going to the other side of the fence which is instant response how do you document how do you handle all that complex uh information that we collect and that's precisely what we're going to be here now. So the floor is yours my friend. >> Thank you Jess. >> Thank you. >> Good afternoon. >> My name is Gintto Anthony. I work for a secure as a senior investigator. It's previously it was known as F-Secure for …