Focused tools for the
investigation loop.
Author detections, triage suspicious email, and explain cloud activity—all in isolated, dependency-free local workspaces.
Detection Rule Studio
Create, validate, replay, tune, version, and document Sigma, YARA, and generic SIEM detections.
- Portable rule editor
- Local event replay
- ATT&CK coverage
Phishing Triage Workbench
Parse suspicious messages, compare sender identity, defang indicators, categorize intent, and record a verdict.
- Local .eml parsing
- Explainable categorization
- Investigation reports
Cloudscope
Normalize multi-cloud audit logs, surface significant activity, connect entities, and explain what changed.
- AWS, Azure, GCP & Kubernetes
- Incident timeline
- Entity and resource mapping
01
Private by designParsing and analysis happen entirely on-device.
02
Transparent evidenceEvery signal remains visible and reviewable.
03
Separate workspacesEach tool owns its state, files, and workflows.