CloudLog
Local-first security investigation & decision support — built by Praharsh.
What happened in this log, in plain English — start here.
Click Upload log above, or pick a sample source in the sidebar.
A plain-English verdict: what looks like an attack, and what to do first.
Open Investigate, hit 🔎 on an incident, and click any IP or user to follow the trail.
How the Summary works — what these numbers mean
- Your allow-list wins first (→ Info), then your block-list (→ Malicious).
- An already-blocked threat rated low is downgraded to Suspicious (it was mitigated).
- Hard indicators (
mimikatz,ransomware, C2 names…) → Malicious. - The source's own severity is honoured: Critical→Malicious, High/Medium→Suspicious, Low/Info→Info.
- OWASP payload signatures (SQLi, XSS, SSRF…) matched in the raw request → Malicious/Suspicious.
- Everything else is Info (normal telemetry).
Log Summary
No log loaded yet. Upload a file or pick a sample source from the sidebar.
Every event, one per row — search, click an IP or user to focus, click a row for full detail.
How the Timeline works
Event Timeline
| Severity | Time (UTC) | Actor | Action | IP | Source |
|---|---|---|---|---|---|
| No events loaded. Upload a file or pick a source from the sidebar. | |||||
Event Details
Select a row to inspect the raw event.
What the rules flagged and why — real findings first, repeated verdict echoes collapsed at the bottom.
How Detections work — the evaluation basis
- Per-event signatures — a regex/keyword matches one event (e.g.
UNION SELECT→ SQLi,sekurlsa→ credential dumping). Payloads are decoded first (URL/entity/comment) so encoded attacks still match. - Aggregate rules — a pattern across many events (e.g. brute force = 3+ failed logins from one source IP).
Suspicious Pattern Detections
No detections yet. Load a log source to run analysis.
Related events grouped into attack chains, in time order.
How the Attack Chain works
Connected Event Chain
No chain yet. Load a log source to build the sequence.
Actor Activity Chain (legacy list)
No activity chain yet. Load a log source to build the sequence.
A picture of how users, IPs and events connect.
How to read the Evidence Graph
- Colour = type — user, IP, host, domain, hash (one column each).
- Ring = risk — red high, amber medium, white low.
- Size = event count — bigger dot, more activity.
- Edges = typed relationships —
logged_into,connected_to,resolved_to,dumped_creds_on… hover or click to trace.
Evidence Graph
Typed relationships between entities — logged_into · executed_on · connected_to · resolved_to · dumped_creds_on. Click a node to trace its connections.An analyst-style written briefing of the whole log (optional AI explanations).
How the AI Analyst works — and what runs locally
If you add your own API key, it can draft a written explanation of the findings — but it never decides severity, and nothing is sent anywhere unless you opt in with a key.
AI Analyst
On-device triage. Optional cloud Q&A is opt-in and sends only a redacted summary.Load a log source to generate an AI analyst report.
Ask AI about this incident (optional)
Incidents ranked P1–P3 by urgency — open 🔎 on one to see everything about it.
How Investigate works — correlation, priority & scoring
- Correlation — events are merged when they share a source IP, actor, hash, or domain (within a time window). A hub guard stops unrelated attackers being merged just because they touched the same popular indicator.
- Priority (P1/P2/P3/Ignore) — from severity, multi-stage progression, and credential/privilege signals.
- Risk — 0–100, weighted down by Confidence so a shaky call can't read as certain.
- Scenario — matches known shapes (Account Takeover, Web Exploitation, Ransomware…).
- Entity Risk — scores each user/IP across all their events.
Correlated Attack Chains
Events auto-linked by shared public IP, actor, hash, or domain within a time window.Load logs to auto-correlate attack chains.
Indicators & Threat Intel
🔑 Add API keys here (you run this locally)
Keys stay in memory only (cleared on refresh). Browsers block direct calls to VirusTotal, AbuseIPDB, OTX, Shodan & GreyNoise (CORS) — those still need the local proxy. Geo/ASN needs no key and works right here. urlscan & Safe Browsing may work directly.
Load logs to extract indicators.
Your manual search bench — use a one-click hunt below or build your own filters.
How Hunt works — investigate on your own
Hunt — build your own filters
Load logs, then filter here to investigate on your own.