Exit
Incident response workspace

Upload Incident Evidence

CyberTrace AI correlates forensic evidence from multiple sources and reconstructs a unified incident timeline.

Evidence encrypted in transit
01

Evidence intake

Drop supported plain-text evidence files

0 FILES
Supported Evidence Sources

Windows Logs

Windows event data exported as plain text

Supported formats

TXT • LOG • CSV

Firewall Logs

Firewall activity exported as plain text

Supported formats

TXT • LOG • CSV

Email Evidence

Email indicators exported as plain text

Supported formats

TXT • LOG • CSV

Network Logs

Network activity exported as plain text

Supported formats

TXT • LOG • CSV

Evidence is sent securely when the investigation starts

AI agent workflow

Agents initialize after evidence intake

Waiting
01

Evidence Parser Agent

Validates and normalizes artifacts

Waiting
02

Timeline Reconstruction Agent

Correlates events across sources

Waiting
03

MITRE ATT&CK Mapping Agent

Maps observed tactics and techniques

Waiting
04

Threat Analysis Engine

Reasons across the complete incident

Waiting
05

Response Planning Engine

Prepares prioritized response actions

Waiting
02

Investigation summary

AI-generated incident findings

Awaiting incident evidence.

Upload one or more artifacts to begin building the investigation report.