Investigation
Easy Mode Workflow
Follow the investigation path without exposing parser, correlation, rule, or performance configuration.
Investigation Principles
What the source record directly establishes.
What the investigator notices.
What the evidence may imply.
A proposition requiring more evidence.
A determination supported by available evidence.
Recent Activity
Evidence Ingestion
Parser Registry
Dedicated parsers normalize common security evidence into CHRONICLE's event model while preserving the complete parser output under SOURCE-SPECIFIC FIELDS. Direct binary EVTX parsing remains a future capability; export EVTX to XML/CSV/JSON for this release.
Evidence Sources
Source Health
| Source | Parser | Records | Normalized | Warnings | Missing Time | Duplicates | Data Gaps | Time range | SHA-256 | Hash Basis |
|---|
Investigation Evidence Tracking
Lightweight custody and acquisition metadata for investigation use. This does not by itself establish a legally sufficient forensic chain of custody.
| Evidence ID | Source | Acquired By | Acquisition | Imported By | SHA-256 | Hash Basis |
|---|
Data Quality Analysis
Import Batches
Each file-selection or drop operation is tracked as a removable ingestion batch.
| Bookmark | Time | Source | Host | Actor | Event | Category | Result | Relevance | Tags |
|---|
Investigative Threads
Structured Finding
A finding keeps evidence, observation, inference, impact, and conclusion distinguishable. Evidence is linked by immutable event ID.
Conclusion
Conclusions are explicit determinations that can reference one or more findings. They do not change the underlying findings or evidence.
Findings
Every evidence link resolves back to a normalized event and its original source record.
Conclusions
STORY MODE
Curated evidence narrative. Story items reference existing events; narration never replaces the source record.
Entities
Entities are extracted from imported evidence. Extraction does not merge or reinterpret source records.
Entity Index
Entity Detail
ENTITY ASSOCIATION
Record that two identifiers may represent the same person, device, or resource for a defined period. This never collapses the underlying entities.
Correlation Engine
Suggestions are temporal/entity relationships only. Proximity or shared identifiers do not establish causation.
Correlation Review
Time Intelligence
Original timestamps remain immutable. Time interpretation and clock correction alter only CHRONICLE's normalized timeline model and are recorded in project provenance.
Source Time Interpretation
Timestamp Diagnostics
| Source | Mode | Zone / offset | Correction | Confidence | Parsed | Unknown | Range |
|---|
Source Clock Comparison Matrix
Cells show the latest recorded model's correction for the column source relative to the row source. A dash means no investigator-recorded clock model exists for that pair.
Clock Skew Workbench
Compare two source clocks using investigator-selected event pairs. Candidate anchors are suggestions based on shared entities and temporal proximity; they are not proof that the events are the same real-world action.
Supporting Event Pairs
Recorded Clock Models
Sessions & Specialized Correlation
Session boundaries, DHCP identity enrichment, and authentication patterns are investigative suggestions. They never replace or modify imported source evidence.
Session Detection
DHCP Lease Intelligence
CHRONICLE tracks time-bounded lease evidence and can enrich IP-address events with a PROBABLE DEVICE for the matching interval. The IP-to-device relationship remains an interpretation, not a permanent entity merge.
Authentication Lead Analysis
Rule Engine & Leads
Rules run locally against normalized events. Matches create investigator-reviewable LEADS, never findings or conclusions.
Rule Library
Rule Lead Review
Rule Editor
WHEN — all conditions
WHEN A — FOLLOWED BY B
Test Results
Specialized Views
Focused projections of normalized evidence. These views do not create new evidence or alter source records.
Process Timeline
Focused Evidence
Process Relationships
Parent/child relationships derived from normalized source fields or explicit process-launch text.
Focused Detail
Comparison Mode
Compare two normalized-time periods. Results are descriptive observations, not anomaly or causation determinations.
Period A · Baseline / Before
Period B · Incident / After
| Dimension | Value | Period A | Period B | Change | Observation |
|---|
Saved Views
Saved views capture search, simple filters, time window, lane mode, and nested advanced-filter groups.
Custom Tags
Performance Diagnostics
Live instrumentation for CHRONICLE's local large-dataset pipeline. Values describe this browser session; they are not evidence findings.
Event Store & Index
Release Readiness Self-Check
Runs local structural checks against the active build and project. This does not modify evidence and is not a forensic validation of source truth.
Large Dataset Controls
Case Notes
Notes autosave with the investigation. Use event annotations when a statement must be explicitly classified as evidence, observation, inference, hypothesis, or conclusion.
Export Investigation
Exports are generated locally. Timeline CSV protects spreadsheet cells beginning with formula characters.
Evidence Integrity Manifest
No evidence sources.
Audit Trail
Meaningful project actions only; routine navigation and display changes are intentionally omitted.
| Time | Actor | Category | Action | Object | Detail |
|---|