03 / CASE STUDY
Windows event analysis
Separate actors, targets and group members before correlating events.
Open offline demo →Developed with AI coding assistance; validated through documented automated tests. I defined the project goals and reviewed the delivered results. AI agents assisted with implementation and executed the documented automated tests.

Challenge
Correlate Windows activity without confusing the actor, target account, added member or group.
Environment
Offline JavaScript Windows-event CSV analyzer. Fictional fixtures, structured identity fields, explicit-timezone timestamps; 10 MiB / 50,000-row limits.
Built
Event learning guide, findings with evidence rows, capture dashboard, filters and timeline. Rules cover repeated failures, failure-before-success, account creation, privileged membership, audit clearing and service installation.
Tested
Existing regressions cover domain separation, actor/member confusion, null SIDs, reversed or ambiguous times and metadata preservation. Actual-browser fixture and File/DataTransfer tests are documented in the sibling project; copied tests and demo navigation are rerun for this portfolio.
Concepts
Identity roles, conservative SID/name matching, chronological evidence and contextual triage.
Outcomes
The password-guessing fixture has six events and two findings. Account-persistence has two events and three overlapping findings. Distinct investigation events are not a numerical risk score.
Takeaways
Names alone are weak correlation evidence. Missing identity and ambiguous timestamps remain unknown rather than being filled with assumptions.
Limitations
No EVTX parsing, AD queries or forensics. No configurable time window. PowerShell and service activity are contextual, not automatically malicious. Windows export guidance was documented but not executed on this Linux host.