// artifact family

casb / cloud app security forensics

10 browser-only forensics tools in this catalog group — browse by artifact family when you know the kind of evidence you are working with, not the investigation pattern.

tools
10
catalog slugs
10
processing
local · in browser

tools in this family

ordered as in the forensics catalog. every tool runs locally — no upload, no account.

  1. zscaler casb cloud app log forensic analyzerdrop zscaler casb log export · parse app + activity + policy · runs locally
  2. microsoft defender cloud apps alert forensic analyzerdrop defender cloud apps alert export · parse app + user + risk · runs locally
  3. forcepoint casb activity log forensic analyzerdrop forcepoint casb export · parse cloud app + action + user · runs locally
  4. bitglass casb audit log forensic analyzerdrop bitglass audit export · parse app + dlp + session · runs locally
  5. mcafee mvision cloud activity log forensic analyzerdrop mvision cloud export · parse app + event + policy · runs locally
  6. casb shadow it app detectordrop casb app discovery export · detect unsanctioned cloud apps · runs locally
  7. casb oauth token abuse detectordrop casb oauth grant export · detect excessive scope grants · runs locally
  8. casb cloud download anomaly detectordrop casb download log export · detect bulk exfiltration bursts · runs locally
  9. multi casb saas activity correlatordrop 2+ casb activity exports · unified saas timeline graph · runs locally
  10. cross casb identity cloud app correlatordrop casb + iam exports · correlate cloud app user to account · runs locally
ready