1 / Load a capture
Authorized educational analysis only. All processing stays in this tab; nothing is stored or sent.
Or drop a CSV here.
Choose a fictional demo or a CSV.
2 / Capture overview
Events needing investigation = distinct events referenced by findings, not a risk score. Counts remain capture-wide when filtering.
Event ID breakdown
Top failed-logon accounts
3 / Findings
4 / Event explorer
Trustworthy timeline
Only ISO timestamps with an explicit timezone are ordered. Unknown/locale timestamps stay visible in the explorer, never inferred.
Analyst workflow
- Confirm authorization and export scope.
- Check audit policy, channel, hosts, and capture coverage.
- Inspect parsing and timestamp caveats.
- Compare failed and successful logons by target account/domain.
- Check source IP, host, workstation and logon type.
- Validate account creation and member-to-group identity against approvals.
- Review log clearing, processes, scripts and services in context.
- Document evidence, benign alternatives, missing logs and next steps.
Event learning guide
Missing events do not prove absence. Audit configuration, retention, locale and export completeness matter. This tool does not replace a SIEM or professional investigation.