// artifact family
database audit trail forensics
10 browser-only forensics tools in this catalog group — browse by artifact family when you know the kind of evidence you are working with, not the investigation pattern.
tools in this family
ordered as in the forensics catalog. every tool runs locally — no upload, no account.
- postgresql pgaudit log forensic analyzerdrop postgresql pgaudit export · parse statement + role + object · runs locally
- mysql enterprise audit log forensic analyzerdrop mysql enterprise audit export · parse query + user + host · runs locally
- sql server audit specification forensic analyzerdrop sql server audit export · parse action + object + login · runs locally
- db2 audit log forensic analyzerdrop db2 audit log export · parse event + authid + object · runs locally
- sap hana audit log forensic analyzerdrop sap hana audit export · parse statement + user + schema · runs locally
- database privilege escalation detectordrop db audit export · detect grant/revoke privilege spikes · runs locally
- ddl change burst anomaly detectordrop db ddl audit export · detect burst schema change events · runs locally
- sensitive table access detectordrop db access audit export · detect off-hours sensitive table reads · runs locally
- multi database audit timeline correlatordrop 2+ db audit exports · unified query timeline graph · runs locally
- cross database identity login correlatordrop db audit + iam exports · correlate db login to active accounts · runs locally