What Nostradamus The Evidence Actually Is

Nostradamus The Evidence is a digital investigation and forensic documentation framework. It allows you to capture, chain-of-custody track, and validate data sources for legal or compliance purposes. The core idea is simple: you feed it raw evidence files, and it outputs a verifiable integrity report that shows nothing was altered after collection. The tool itself is a Python-based toolkit that wraps around established libraries. It uses cryptographic hashing (SHA-256 by default), timestamping via RFC 3161 timestamps, and produces JSON-based audit trails. Most people download it from GitHub under the name "nostradamus-evidence" or similar. It is open source, which means the code is visible but also means you are responsible for your own security review before using it in anything that matters.

Nostradamus The Evidence Setup and First Run

I installed it on a clean Ubuntu 22.04 VM first, because running unvetted Python tools on a production machine is how you get pwned. The installation is straightforward if you follow the README exactly.

git clone https://github.com/nostradamus-evidence/nostradamus-evidence.git cd nostradamus-evidence pip install -r requirements.txt

python setup.py install

After that, the basic command to hash a file looks like this:

nostradamus evidence collect --input /path/to/evidence.jpg --output ./case_001/ Overwriting existing cases: If you run the collect command against a directory that already contains output from a previous run, the tool will overwrite the manifest without warning. Always double-check your output path. Hash collisions are theoretically possible: The tool uses SHA-256, which is industry standard, but if you are dealing with adversarial evidence where someone is intentionally crafting collision pairs, you need to layer in a second hash algorithm. The tool supports specifying a secondary hash with the --secondary-hash sha3-512 flag.

Get the Full Details

Nostradamus: The Evidence : Wilson, Ian: Amazon.in: Books
Nostradamus: The Evidence : Wilson, Ian: Amazon.in: Books

Network timestamps can drift: The RFC 3161 timestamping depends on a functioning NTP connection. If your system clock is off by more than a few seconds, the timestamp will be wrong and the entire audit trail becomes suspect. Check your system time before you start any evidence collection session.

When This Tool Fails Completely

Nostradamus The Evidence is not a general-purpose forensic suite. It does not image drives, it does not carve deleted files, and it does not handle mobile device extraction. If you need those capabilities, use something like Autopsy or Cellebrite alongside it. The tool is specifically designed for evidence documentation and integrity verification after you have already collected the raw data. It also does not integrate well with Windows Event Logs. I tried piping EVTX files through the collector and got inconsistent metadata results. The tool assumes Unix-style file attributes by default. If you are working primarily in a Windows environment, you need to use the --platform windows flag and test your output carefully before relying on it.

Advanced Usage

If you are running this at scale, the batch mode is worth learning. Instead of processing one file at a time, you can point the tool at a directory and it will recursively collect everything.

nostradamus evidence collect --recursive --input /evidence_dump/case_047/ --output ./case_047_verified/

This processes the entire directory tree and generates a single consolidated report. The recursive mode respects the same timestamping and hashing rules as individual file processing. It is significantly faster than running the tool file-by-file in a loop. For legal proceedings, you may want to export the audit trail in a format that your jurisdiction accepts. The tool supports exporting to PDF and CSV. The PDF export includes the full manifest with visual hash verification codes. That is useful when you need to present findings to a judge or opposing counsel who will not look at raw JSON.

nostradamus report generate --input ./case_047_verified/manifest.json --format pdf --output ./case_047_report.pdf

Nostradamus: The Evidence by Ian Wilson - Orion HC (2002) | eBay
Nostradamus: The Evidence by Ian Wilson - Orion HC (2002) | eBay
I also recommend configuring a local signing key if you plan to use this in a professional capacity. The tool supports GPG signing of the final report. This adds another layer of verification that the report itself has not been tampered with after generation. Without it, someone could modify the JSON and the hashes would still match the original evidence, but the report metadata would be fake. A signed report prevents that.

nostradamus sign --input ./case_047_verified/manifest.json --gpg-key 0xABCD1234

Bottom Line

Nostradamus The Evidence is a solid tool for what it does. It does exactly one thing and does it well. It documents evidence integrity with a clear audit trail. It is not a replacement for proper forensic training or for more comprehensive tools. But if you need a reliable way to capture and verify the integrity of evidence files, this is one of the better open-source options available. The documentation is decent, the community is small but active, and the code is readable if you need to debug something yourself. The biggest issue I see is people treating it like a magic bullet. It is not. It hashes files and logs actions. The quality of your evidence depends entirely on how you collect it before it ever touches this tool.