OFFLINE · SECURITY ANALYSIS LAB

Windows Event Log Triage

Evidence before assumptions. Explore Windows activity without uploading your logs.

1 / Load a capture

Authorized educational analysis only. All processing stays in this tab; nothing is stored or sent.

Or drop a CSV here.

Choose a fictional demo or a CSV.

2 / Capture overview

Events needing investigation = distinct events referenced by findings, not a risk score. Counts remain capture-wide when filtering.

Event ID breakdown

Top failed-logon accounts

3 / Findings

4 / Event explorer

Trustworthy timeline

Only ISO timestamps with an explicit timezone are ordered. Unknown/locale timestamps stay visible in the explorer, never inferred.

    Analyst workflow

    1. Confirm authorization and export scope.
    2. Check audit policy, channel, hosts, and capture coverage.
    3. Inspect parsing and timestamp caveats.
    4. Compare failed and successful logons by target account/domain.
    5. Check source IP, host, workstation and logon type.
    6. Validate account creation and member-to-group identity against approvals.
    7. Review log clearing, processes, scripts and services in context.
    8. Document evidence, benign alternatives, missing logs and next steps.

    Event learning guide

    Missing events do not prove absence. Audit configuration, retention, locale and export completeness matter. This tool does not replace a SIEM or professional investigation.