Skip to content
Critical Vulnerability CVE-2026-40493 in SAIL Library: A Deep DiveRead

Investigation & Forensics

Offline Investigation

Upload log files and analyse them in isolation.

Available as a standalone module · Add to my package
Offline InvestigationLive
8Open cases
1,284Entities linked
23Techniques mapped
  • Many log formatsActive
  • Watched foldersActive
  • Full SIGMA and YARA pipelineActive
  • Evidence preserved per caseActive
Illustrative view of the Awiron console

What it does

Upload EVTX, JSON, CSV or syslog exports, or watch a server path, and run the full detection pipeline without connecting the source system.

Many log formats

Watched folders

Full SIGMA and YARA pipeline

Evidence preserved per case

Live demo

Runs in your browser on sample data. Click around, nothing here touches a real system.

Awiron Offline Investigation — Attack Timeline Reconstruction
Drop log file or click to upload
Supports: .evtx, .json, .csv, .pcap, .log — up to 2GB

How it worksin three steps.

  1. Gather evidence

    Pull logs, incidents and uploaded files into a single case.

  2. Reconstruct

    Entities, correlations and a timeline rebuild the attack step by step.

  3. Report

    Share findings with the team or export an executive PDF.

Ready to see it on your own data?

A 30-minute walkthrough with an engineer, tailored to your environment.