What Nostradamus The Evidence Actually Is
Nostradamus The Evidence is a digital investigation and forensic documentation framework. It allows you to capture, chain-of-custody track, and validate data sources for legal or compliance purposes. The core idea is simple: you feed it raw evidence files, and it outputs a verifiable integrity report that shows nothing was altered after collection. The tool itself is a Python-based toolkit that wraps around established libraries. It uses cryptographic hashing (SHA-256 by default), timestamping via RFC 3161 timestamps, and produces JSON-based audit trails. Most people download it from GitHub under the name "nostradamus-evidence" or similar. It is open source, which means the code is visible but also means you are responsible for your own security review before using it in anything that matters.Nostradamus The Evidence Setup and First Run
I installed it on a clean Ubuntu 22.04 VM first, because running unvetted Python tools on a production machine is how you get pwned. The installation is straightforward if you follow the README exactly.git clone https://github.com/nostradamus-evidence/nostradamus-evidence.git cd nostradamus-evidence pip install -r requirements.txt
python setup.py install
nostradamus evidence collect --input /path/to/evidence.jpg --output ./case_001/ Overwriting existing cases: If you run the collect command against a directory that already contains output from a previous run, the tool will overwrite the manifest without warning. Always double-check your output path. Hash collisions are theoretically possible: The tool uses SHA-256, which is industry standard, but if you are dealing with adversarial evidence where someone is intentionally crafting collision pairs, you need to layer in a second hash algorithm. The tool supports specifying a secondary hash with the --secondary-hash sha3-512 flag.
Get the Full Details

Network timestamps can drift: The RFC 3161 timestamping depends on a functioning NTP connection. If your system clock is off by more than a few seconds, the timestamp will be wrong and the entire audit trail becomes suspect. Check your system time before you start any evidence collection session.
When This Tool Fails Completely
Nostradamus The Evidence is not a general-purpose forensic suite. It does not image drives, it does not carve deleted files, and it does not handle mobile device extraction. If you need those capabilities, use something like Autopsy or Cellebrite alongside it. The tool is specifically designed for evidence documentation and integrity verification after you have already collected the raw data. It also does not integrate well with Windows Event Logs. I tried piping EVTX files through the collector and got inconsistent metadata results. The tool assumes Unix-style file attributes by default. If you are working primarily in a Windows environment, you need to use the--platform windows flag and test your output carefully before relying on it.
Advanced Usage
If you are running this at scale, the batch mode is worth learning. Instead of processing one file at a time, you can point the tool at a directory and it will recursively collect everything.nostradamus evidence collect --recursive --input /evidence_dump/case_047/ --output ./case_047_verified/
nostradamus report generate --input ./case_047_verified/manifest.json --format pdf --output ./case_047_report.pdf

nostradamus sign --input ./case_047_verified/manifest.json --gpg-key 0xABCD1234