Cases
Every case that has run, with its current status. Open one to see its investigation, or start a new one.
Investigations
Business cases, shown with every technique attached to them -- the same grouping you see when starting one. A technique-case that's part of one of these also appears in Case history below, since it's still a real, independently-run case.
Loading…
Case history
Loading…
Archived cases
Cases moved out of the working list. Nothing is deleted; archiving only hides a case here.
Loading…
Tool runs
Standalone single-tool runs, kept separate from cases above -- no rule engine ran here, so there is no Finding/Hypothesis synthesis behind these, only the tool's own raw output and the analyst's note. Click a run to see its full output.
Loading…
Archived tool runs
Nothing is deleted; archiving only hides a run here.
Loading…
Run one tool, standalone
For when you want to run a single technique on a single input without starting a full case. There is no rule engine here -- you get the tool's own raw output plus your note, not a synthesized Finding.
Choose a case to open
Both paths below run the same investigation process: evidence intake, automated analysis, and a human review step before a case is closed. The only difference is where the evidence comes from.
Quick demo: sample data
Runs instantly against the bundled synthetic dataset. No files to collect.
Loading…
Real investigation: your own evidence
Shows exactly what to collect and the commands to collect it, then runs your upload through the same pipeline.
Loading…
Coming soon
On the roadmap. Shown so you can see where this is headed, not selectable yet.
Which technique(s) does this investigation need?
Start with one or more now; you can attach additional techniques to this investigation later, from its hub, as the case develops.
Loading…
Attached techniques
Loading…
Attach another technique
Loading…
Close investigation
Loading…
Comments0
Handoff
Settings
Configuration for the optional AI-assisted review step. The standard automated checks always run on every case regardless of what's set here.
AI assistant
Anthropic key, when it gets used, and a daily spending cap.
API key
Daily budget
Once today's spend reaches the cap, every case falls back to rules-only for the rest of the day. Pricing is an estimate, see cost_tracking.py.
When should it run?
A configured key does not by itself mean every inconclusive case gets an automatic review. Choose here, or request one yourself per case from that case's review screen regardless of this setting.
Reputation services
Used by the URL/domain reputation enrichment tool, which only runs when a case has a URL and at least one of these is set. Macro analysis, domain age, and homoglyph checks need no key at all.
Google Safe Browsing
VirusTotal
Users
Everyone with access, across all three roles. Admins can create new accounts here; passwords are set once at creation and shown only to you, this one time.
New user
Loading…