← All projects

03 / CASE STUDY

Windows event analysis

Separate actors, targets and group members before correlating events.

Open offline demo →

Developed with AI coding assistance; validated through documented automated tests. I defined the project goals and reviewed the delivered results. AI agents assisted with implementation and executed the documented automated tests.

Actual windows event analysis interface with a fictional training sample
Real Firefox screenshot · fictional bundled data only.

Challenge

Correlate Windows activity without confusing the actor, target account, added member or group.

Environment

Offline JavaScript Windows-event CSV analyzer. Fictional fixtures, structured identity fields, explicit-timezone timestamps; 10 MiB / 50,000-row limits.

Built

Event learning guide, findings with evidence rows, capture dashboard, filters and timeline. Rules cover repeated failures, failure-before-success, account creation, privileged membership, audit clearing and service installation.

Tested

Existing regressions cover domain separation, actor/member confusion, null SIDs, reversed or ambiguous times and metadata preservation. Actual-browser fixture and File/DataTransfer tests are documented in the sibling project; copied tests and demo navigation are rerun for this portfolio.

Concepts

Identity roles, conservative SID/name matching, chronological evidence and contextual triage.

Outcomes

The password-guessing fixture has six events and two findings. Account-persistence has two events and three overlapping findings. Distinct investigation events are not a numerical risk score.

Takeaways

Names alone are weak correlation evidence. Missing identity and ambiguous timestamps remain unknown rather than being filled with assumptions.

Limitations

No EVTX parsing, AD queries or forensics. No configurable time window. PowerShell and service activity are contextual, not automatically malicious. Windows export guidance was documented but not executed on this Linux host.