Investigation engine for Microsoft Defender, Sysmon and Windows event logs

Logs in. Investigation out.

TraceSec turns a pile of endpoint and identity events into something an analyst can act on: what happened, why it matters, how sure we are, and what to do next. Every verdict is grounded in the evidence it cites, and every alert is weighed against what the environment normally does.

Analyze your logsHow it works
Privacy mode: users, devices and IPs are pseudonymized before analysisPaste or upload: Advanced Hunting CSV, Event Viewer XML/CSV, JSON, textRule engine always on · Claude explanation optional

Try it with your own events

Paste events or drop an export file: a CSV from Defender Advanced Hunting, an Event Viewer export (XML or CSV), Sysmon or JSON, or plain text. Identities are replaced in your browser before anything is sent.

Load an example:
6 events4 identifiers pseudonymized
Claude + rule engine

Results open as an investigation page and stay in this browser. Create an account to keep investigations, share them with your team and use the dashboard.

How it works

Three stages, each visible in the result. Nothing is a black box: the classification and the context are shown next to the verdict.

01 · Paste it or drop the export

No agents, no connectors

An analyst pastes the rows from Advanced Hunting or drops the export file. Timestamps, processes, parents, accounts, devices and addresses are extracted, and identities are replaced before anything is analyzed.

AccountName: CORP\m.huber → USER_0001
RemoteIP: 185.220.101.7 → EXTERNAL_IP_001
02 · Classify

Expected, unusual, suspicious

Thirty behavioral rules cover execution, persistence, credential access, lateral movement and impact. Context that argues for legitimacy, such as a deployment agent, a signed binary or fleet prevalence, counts just as much.

✓ Expected signed winword.exe
⚠ Unusual powershell.exe for this user
! Suspicious Word → PowerShell, encoded
03 · Explain and recommend

An investigation, not an alert

The findings become a case: summary, evidence with cited events, MITRE techniques, the false-positive balance, prioritized next steps and the queries to run. With Claude enabled, the explanation reads like a senior analyst wrote it.

High risk · 92 % Further investigation recommended
P1 Inspect the dropped file and decoded command

What you get

Built for SOC teams and MSSPs that run on Microsoft Defender and need to explain verdicts to customers, not just produce them.

Behavior classification

Expected, unusual and suspicious are separate buckets. An unusual event with a legitimate explanation never gets the same weight as a known technique.

Evidence, not vibes

Each finding cites the exact events, the technique and why it deviates from normal. Nothing in the verdict is unsourced.

False-positive balance

Both sides of the evidence before a verdict, plus a scale from "likely legitimate" to "likely malicious" so a customer can see why a case was closed.

KQL, ready to run

Every recommended step that needs data comes with the Advanced Hunting query, explained in one sentence.

Privacy mode

Identities are pseudonymized in the browser and in every report. Multi-tenant by design, so one MSSP account serves many customers without mixing data.

Your choice of engine

The rule engine runs on its own and costs nothing per case. Claude's explanation is a per-tenant switch, and a self-hosted model can take its place.

Keep your investigations

Anonymous analyses stay in your browser. With an account, every investigation is stored for your tenant, shows up in the dashboard with status and assignee, and can be shared with your team.