CloudLog

Local-first security investigation & decision support — built by Praharsh.

Total events0
Unique actors0
Unique IPs0
Time span-
Active sourceNone
Detections0
Summary
Timeline
Detections
Attack Chain
Evidence Graph
AI Analyst
Investigate
🔎 Hunt

What happened in this log, in plain English — start here.

Welcome to CloudLog
A single-file security log triage tool that runs entirely in your browser — nothing is sent anywhere.
1
Load a log
Click Upload log above, or pick a sample source in the sidebar.
2
Read the summary
A plain-English verdict: what looks like an attack, and what to do first.
3
Investigate
Open Investigate, hit 🔎 on an incident, and click any IP or user to follow the trail.
Supports JSON, CSV, syslog, CEF, Apache, Zeek, AWS GuardDuty, Windows/Sysmon, Splunk/Wazuh/Sentinel. A heuristic triage assistant — it flags common, known attack patterns to help you look faster; it doesn't replace a SIEM.
How the Summary works — what these numbers mean
Every event is sorted into Malicious, Suspicious, or Info by a fixed order of checks:
  • Your allow-list wins first (→ Info), then your block-list (→ Malicious).
  • An already-blocked threat rated low is downgraded to Suspicious (it was mitigated).
  • Hard indicators (mimikatz, ransomware, C2 names…) → Malicious.
  • The source's own severity is honoured: Critical→Malicious, High/Medium→Suspicious, Low/Info→Info.
  • OWASP payload signatures (SQLi, XSS, SSRF…) matched in the raw request → Malicious/Suspicious.
  • Everything else is Info (normal telemetry).
This is deterministic heuristic triage, not ML — the same input always gives the same result. Wrong call? Use 👎 on a row, or add an allow/block/custom rule in Investigate.

Log Summary

No log loaded yet. Upload a file or pick a sample source from the sidebar.

Every event, one per row — search, click an IP or user to focus, click a row for full detail.

How the Timeline works
Events are ordered by their timestamp and tagged with an attack stage (Reconnaissance → Initial Access → Execution → Persistence → Credential Access → Lateral Movement → Exfiltration → Impact). The stage is inferred per event from its action text and matched MITRE technique.
If timestamps are missing or in an odd format, ordering may be approximate — check the raw event. Stage names come from keyword/technique matching, so a mis-tagged stage usually means a rule needs tuning.

Event Timeline

SeverityTime (UTC)ActorActionIPSource
No events loaded. Upload a file or pick a source from the sidebar.

Event Details

Select a row to inspect the raw event.

What the rules flagged and why — real findings first, repeated verdict echoes collapsed at the bottom.

How Detections work — the evaluation basis
Each row is a MITRE ATT&CK technique whose pattern matched your data. Two kinds of rules run:
  • Per-event signatures — a regex/keyword matches one event (e.g. UNION SELECT → SQLi, sekurlsa → credential dumping). Payloads are decoded first (URL/entity/comment) so encoded attacks still match.
  • Aggregate rules — a pattern across many events (e.g. brute force = 3+ failed logins from one source IP).
Rows are grouped by technique — "120 events (49 sources)" means the rule fired for 49 separate sources.
Signatures catch known patterns; a novel payload with no matching rule won't show here. You can add your own patterns under Investigate → Custom rules.

Suspicious Pattern Detections

No detections yet. Load a log source to run analysis.

Related events grouped into attack chains, in time order.

How the Attack Chain works
For a correlated incident, events are laid out in stage order to show the story: how an attacker got in, what they ran, and where they went. Each step links back to the real events behind it.
The chain only reflects what's in the logs — if a stage wasn't logged, it won't appear. Order follows timestamps + stage, so a gap usually means missing telemetry, not a missing step.

Connected Event Chain

No chain yet. Load a log source to build the sequence.

Actor Activity Chain (legacy list)

No activity chain yet. Load a log source to build the sequence.

A picture of how users, IPs and events connect.

How to read the Evidence Graph
Entities are linked by shared activity. The encoding:
  • Colour = type — user, IP, host, domain, hash (one column each).
  • Ring = risk — red high, amber medium, white low.
  • Size = event count — bigger dot, more activity.
  • Edges = typed relationships — logged_into, connected_to, resolved_to, dumped_creds_on… hover or click to trace.
Risk per entity fuses its malicious/suspicious events, failed logins, credential-access and privilege signals.
Click any node to isolate its connections. A dense "hairball" means many shared indicators — click a node to cut through it.

Evidence Graph

Typed relationships between entities — logged_into · executed_on · connected_to · resolved_to · dumped_creds_on. Click a node to trace its connections.
Click any entity to trace its connections across the investigation.

An analyst-style written briefing of the whole log (optional AI explanations).

How the AI Analyst works — and what runs locally
Detection happens locally first — the rules above do the work with no network calls. This tab only summarises: it groups and de-duplicates the detections into a plain-language narrative, and the gauge shows the share of events that were flagged.

If you add your own API key, it can draft a written explanation of the findings — but it never decides severity, and nothing is sent anywhere unless you opt in with a key.
Treat the narrative as a first draft for a human analyst, not a verdict. The underlying facts are the detections and evidence, not the prose.

AI Analyst

On-device triage. Optional cloud Q&A is opt-in and sends only a redacted summary.

Load a log source to generate an AI analyst report.

Ask AI about this incident (optional)

🔒 Local-first. The report above is generated entirely on your device. This box is the only feature that can send data off-device, it is off until you use it, it needs your own API key for the provider you pick, and it transmits only the redacted aggregate summary shown below — never raw logs, full IPs, or identities.
▸ Preview exactly what will be sent
The answer will appear here.

Incidents ranked P1–P3 by urgency — open 🔎 on one to see everything about it.

How Investigate works — correlation, priority & scoring
Thousands of events are collapsed into a few incidents, each with a Decision Card:
  • Correlation — events are merged when they share a source IP, actor, hash, or domain (within a time window). A hub guard stops unrelated attackers being merged just because they touched the same popular indicator.
  • Priority (P1/P2/P3/Ignore) — from severity, multi-stage progression, and credential/privilege signals.
  • Risk — 0–100, weighted down by Confidence so a shaky call can't read as certain.
  • Scenario — matches known shapes (Account Takeover, Web Exploitation, Ransomware…).
  • Entity Risk — scores each user/IP across all their events.
You control the inputs: add allow-list, block-list, YARA, or custom rules here and everything re-evaluates. Found a wrong call? Adjust a rule and re-run — the logic is transparent by design.

Correlated Attack Chains

Events auto-linked by shared public IP, actor, hash, or domain within a time window.

Load logs to auto-correlate attack chains.

Indicators & Threat Intel

🔑 Add API keys here (you run this locally)

Keys stay in memory only (cleared on refresh). Browsers block direct calls to VirusTotal, AbuseIPDB, OTX, Shodan & GreyNoise (CORS) — those still need the local proxy. Geo/ASN needs no key and works right here. urlscan & Safe Browsing may work directly.

Checking for local threat-proxy…

Load logs to extract indicators.

Your manual search bench — use a one-click hunt below or build your own filters.

How Hunt works — investigate on your own
Your manual workbench. Filter every event by Event ID, event type, IP, user, keyword, severity, source, or time window. The breakdowns and stats update live and every value is clickable, so you can follow a hunch by pivoting. Nothing is decided for you here — you drive.
Keyboard (when this tab is open): / focus search · m malicious · s suspicious · a all · c clear. Click any value (IP, user, Event ID, type) to add it as a filter; each active filter shows as a chip you can remove.

Hunt — build your own filters

Start here — one-click hunts:
💡 Filters combine — an event must match all of them. Click any value in the results below (an IP, a user, an Event ID) to add it as a filter; remove it from the chips above the table.

Load logs, then filter here to investigate on your own.

This workspace is protected
Ask the admin for an access code. Saved cases are AES-256 encrypted.