No Evidence Data Processed
It appears that there is currently no evidence data available for processing or reviewing.
To proceed, please follow these steps:
- Go to Case & Evidence Management: Navigate to the Case & Evidence Management' section of our platform.
- Upload Evidence Data: Here, you can upload your evidence files. Supported formats include:
EVTX files: These files contain event log data from Windows systems.
ZIP Archives: You can also upload a ZIP archive containing your EVTX files for convenience.
Ensure that your files meet these requirements before uploading. Once your evidence data is uploaded, it will be processed, and you will be able to access detailed insights.
Evidence Data Processing in Progress
The system is currently processing the uploaded data. Please wait until the process is complete.
Artifact: IP addresses
The table below contains IP addresses extracted from all data fields (such as IpAddress, DestAddress etc.) of Windows Events identified by Sigma rules. It excludes private, reserved, and special IP address ranges, including:
- Private and reserved adress space (192.168.0.0/24, 100.64.0.0/10, 224.0.0.0/4, etc.)
- Google DNS servers (8.8.8.8, 8.8.4.4)
| Country |
IP Address |
ASN |
Company |
Score |
Detection Count |
| (Data loading) |
Artifact: Usernames
The table below contains usernames extracted from fields SubjectUserName and TargetUserName of Windows Events identified by Sigma rules. It excludes specific user names such as "None", "NO UUSER", as well as usernames ending with "$".
| Username |
Count |
| (Data loading) |
Artifact: Command Lines and ProcessNames