drop evtx files · find logging gaps · detect log clearing · suspicious event sequences · merged timeline · runs locally