// artifact family

identity threat detection & response forensics

10 browser-only forensics tools in this catalog group — browse by artifact family when you know the kind of evidence you are working with, not the investigation pattern.

tools
10
catalog slugs
10
processing
local · in browser

tools in this family

ordered as in the forensics catalog. every tool runs locally — no upload, no account.

  1. okta threat insight export forensic analyzerdrop okta threat insight export · parse actor + risk + event type · runs locally
  2. microsoft entra id protection export forensic analyzerdrop entra id protection export · parse user + risk level + detection · runs locally
  3. crowdstrike identity threat export forensic analyzerdrop crowdstrike identity export · parse account + anomaly + stage · runs locally
  4. sailpoint identity security export forensic analyzerdrop sailpoint identity security export · parse identity + risk score + policy · runs locally
  5. ping identity threat export forensic analyzerdrop ping identity threat export · parse user + risk event + source · runs locally
  6. identity credential stuffing burst detectordrop identity threat export · detect credential stuffing bursts · runs locally
  7. identity impossible travel anomaly detectordrop identity risk export · detect impossible travel patterns · runs locally
  8. identity privilege anomaly correlatordrop identity + iam exports · correlate risk to privilege change · runs locally
  9. multi itdr alert timeline correlatordrop 2+ itdr exports · unified identity risk timeline graph · runs locally
  10. cross itdr edr session correlatordrop itdr + edr exports · correlate identity alert to host session · runs locally
ready