Investigation & Forensics
Log Explorer
Search billions of events in milliseconds.
Available as a standalone module · Add to my package8Open cases
1,284Entities linked
23Techniques mapped
- Elasticsearch backendActive
- Structured and full-text queriesActive
- Field aggregationsActive
- Export to CSV and JSONActive
What it does
Full-text and structured search over every stored event, with time-range and field filters, aggregations and exports.
Elasticsearch backend
Structured and full-text queries
Field aggregations
Export to CSV and JSON
Live demo
Runs in your browser on sample data. Click around, nothing here touches a real system.
| Timestamp | Source | Event ID | Message | Host | Score |
|---|
Event Distribution
How it worksin three steps.
Gather evidence
Pull logs, incidents and uploaded files into a single case.
Reconstruct
Entities, correlations and a timeline rebuild the attack step by step.
Report
Share findings with the team or export an executive PDF.
Works best withthese modules.
See all 30 modules
Detection & Response
Incident Management
Correlated incidents with severity, assets and timeline.
Learn more Threat IntelligenceMITRE ATT&CK Coverage
See which techniques you can detect, with evidence.
Learn more Reporting & GovernanceReports
Template library, builder and scheduled delivery.
Learn moreAlso in Investigation & Forensics
Ready to see it on your own data?
A 30-minute walkthrough with an engineer, tailored to your environment.