Investigation & Forensics
Offline Investigation
Upload log files and analyse them in isolation.
Available as a standalone module · Add to my package8Open cases
1,284Entities linked
23Techniques mapped
- Many log formatsActive
- Watched foldersActive
- Full SIGMA and YARA pipelineActive
- Evidence preserved per caseActive
What it does
Upload EVTX, JSON, CSV or syslog exports, or watch a server path, and run the full detection pipeline without connecting the source system.
Many log formats
Watched folders
Full SIGMA and YARA pipeline
Evidence preserved per case
Live demo
Runs in your browser on sample data. Click around, nothing here touches a real system.
Drop log file or click to upload
Supports: .evtx, .json, .csv, .pcap, .log — up to 2GB
How it worksin three steps.
Gather evidence
Pull logs, incidents and uploaded files into a single case.
Reconstruct
Entities, correlations and a timeline rebuild the attack step by step.
Report
Share findings with the team or export an executive PDF.
Works best withthese modules.
See all 30 modules
Detection & Response
Incident Management
Correlated incidents with severity, assets and timeline.
Learn more Threat IntelligenceMITRE ATT&CK Coverage
See which techniques you can detect, with evidence.
Learn more Reporting & GovernanceReports
Template library, builder and scheduled delivery.
Learn moreAlso in Investigation & Forensics
Ready to see it on your own data?
A 30-minute walkthrough with an engineer, tailored to your environment.