Every investigation starts with a trace.
Analyze a log file to explore related requests, reconstruct events, and keep notes. You can also open a saved investigation above.
Find the right perspective.
Explore the detectors available on this server. Each looks for unusual activity in a different way.
Checking available models…
Follow the trace.
Upload an Apache log file or paste requests to find unusual activity.
Investigations found
Follow related requests from the first unusual event to the last.
The selected detector supplies the candidates. Account and timing connect them into investigations you can review and refine.
The cutoff chooses which requests enter the reconstruction. It is not attack confidence.
When candidate requests occurred
Candidate investigations
Investigation
How this reconstruction was assembled
Sequence of events
Chronological · times in UTC
Compare with earlier activity
Investigation notes
Your interpretation, separate from the observed records.
Edits are kept in this session. Export the report to keep your reconstruction and notes.