Security WorkbenchLocal analyst suite
Local-first toolsYour evidence stays in this browser
ANALYST TOOLKIT / 03 WORKBENCHES

Focused tools for the
investigation loop.

Author detections, triage suspicious email, and explain cloud activity—all in isolated, dependency-free local workspaces.

01 READY
DETECTION ENGINEERING

Detection Rule Studio

Create, validate, replay, tune, version, and document Sigma, YARA, and generic SIEM detections.

  • Portable rule editor
  • Local event replay
  • ATT&CK coverage
Open workspace
02 READY
EMAIL SECURITY

Phishing Triage Workbench

Parse suspicious messages, compare sender identity, defang indicators, categorize intent, and record a verdict.

  • Local .eml parsing
  • Explainable categorization
  • Investigation reports
Open workspace
03 READY
CLOUD INCIDENT RESPONSE

Cloudscope

Normalize multi-cloud audit logs, surface significant activity, connect entities, and explain what changed.

  • AWS, Azure, GCP & Kubernetes
  • Incident timeline
  • Entity and resource mapping
Open workspace
01

Private by designParsing and analysis happen entirely on-device.

02

Transparent evidenceEvery signal remains visible and reviewable.

03

Separate workspacesEach tool owns its state, files, and workflows.