FROM SIGNAL TO UNDERSTANDING
Investigate with evidence.
Upload a log export. Review authentication patterns. Decide where to look next.
This prototype uses two explainable authentication rules. Findings are prompts for review; they do not establish a breach. No AI model or live monitoring is connected.
Start with your security logs
Drop one file here, or choose a file. JSON, JSONL, NDJSON or CSV · up to 5 MiB / 10,000 rows
A FOCUSED FIRST STEP
See the sequence.
Understand the signal.
Identify failure bursts and successful logins following repeated failures. Each finding links back to the events that triggered it.
Supported format and detection rules
Prepare a log export
Use a JSON array, an object with an events array, one JSON object per line, or a CSV with a header row. Timestamps must include an explicit timezone, such as 2026-10-04T09:00:00Z. Events with invalid fields are skipped and listed above.
timestamp,action,outcome,user,source_ip,host,message 2026-10-04T09:00:00Z,login,failure,alex,192.0.2.10,app-01,Invalid credentials
The canonical fields are timestamp, action, outcome, user, source_ip, host and message. An explicit authentication action is required for detection; other valid events remain visible.
Two rules, clear limits
- At least five authentication failures from one IP address within five minutes.
- At least three authentication failures followed by a success for the same account and IP within ten minutes.
Duplicate normalized events are removed before analysis. This version does not detect all threats, infer missing timezones, connect to your environment, or send selected log contents to a server.