Investigation

Easy Mode Workflow

Follow the investigation path without exposing parser, correlation, rule, or performance configuration.

Investigation Principles

EVIDENCE

What the source record directly establishes.

OBSERVATION

What the investigator notices.

INFERENCE

What the evidence may imply.

HYPOTHESIS

A proposition requiring more evidence.

CONCLUSION

A determination supported by available evidence.

Recent Activity

No investigation activity yet.

Evidence Ingestion

Drop timestamped evidence here CSV/TSV, JSON/NDJSON, XML, syslog, Zeek, Suricata, web/firewall/cloud/identity exports · files remain on this device

Preparing import…0%
No active ingestion.

Parser Registry

Dedicated parsers normalize common security evidence into CHRONICLE's event model while preserving the complete parser output under SOURCE-SPECIFIC FIELDS. Direct binary EVTX parsing remains a future capability; export EVTX to XML/CSV/JSON for this release.

Evidence Sources

No evidence imported.

Source Health

SourceParserRecordsNormalizedWarningsMissing TimeDuplicatesData GapsTime rangeSHA-256Hash Basis

Investigation Evidence Tracking

Lightweight custody and acquisition metadata for investigation use. This does not by itself establish a legally sufficient forensic chain of custody.

Evidence IDSourceAcquired ByAcquisitionImported BySHA-256Hash Basis

Data Quality Analysis

Import Batches

Each file-selection or drop operation is tracked as a removable ingestion batch.

No import batches.
Combined chronological timeline
BookmarkTimeSourceHostActorEventCategoryResultRelevanceTags

Investigative Threads

Structured Finding

A finding keeps evidence, observation, inference, impact, and conclusion distinguishable. Evidence is linked by immutable event ID.

Create the finding first, then link supporting events from the Event Inspector.

Conclusion

Conclusions are explicit determinations that can reference one or more findings. They do not change the underlying findings or evidence.

Findings

Every evidence link resolves back to a normalized event and its original source record.

Conclusions

STORY MODE

Curated evidence narrative. Story items reference existing events; narration never replaces the source record.

Entities

Entities are extracted from imported evidence. Extraction does not merge or reinterpret source records.

Entity Index

No entities indexed.

Entity Detail

Select an entity.

ENTITY ASSOCIATION

Record that two identifiers may represent the same person, device, or resource for a defined period. This never collapses the underlying entities.

Correlation Engine

Suggestions are temporal/entity relationships only. Proximity or shared identifiers do not establish causation.

PROPOSED CORRELATION — investigator acceptance is required before a suggestion is treated as an accepted relationship.

Correlation Review

Time Intelligence

Original timestamps remain immutable. Time interpretation and clock correction alter only CHRONICLE's normalized timeline model and are recorded in project provenance.

TIME IS UNCERTAIN. A correction is an investigator-controlled interpretation, not a modification of source evidence.

Source Time Interpretation

Timestamp Diagnostics

SourceModeZone / offsetCorrectionConfidenceParsedUnknownRange

Source Clock Comparison Matrix

Cells show the latest recorded model's correction for the column source relative to the row source. A dash means no investigator-recorded clock model exists for that pair.

Clock Skew Workbench

Compare two source clocks using investigator-selected event pairs. Candidate anchors are suggestions based on shared entities and temporal proximity; they are not proof that the events are the same real-world action.

Supporting Event Pairs

No supporting pairs selected.

Recorded Clock Models

No clock models recorded.

Sessions & Specialized Correlation

Session boundaries, DHCP identity enrichment, and authentication patterns are investigative suggestions. They never replace or modify imported source evidence.

PROPOSED CORRELATION. Session pairing and probable DHCP identity must be reviewed in context. Authentication analysis creates leads, not findings.

Session Detection

DHCP Lease Intelligence

CHRONICLE tracks time-bounded lease evidence and can enrich IP-address events with a PROBABLE DEVICE for the matching interval. The IP-to-device relationship remains an interpretation, not a permanent entity merge.

Authentication Lead Analysis

Rule Engine & Leads

Rules run locally against normalized events. Matches create investigator-reviewable LEADS, never findings or conclusions.

INVESTIGATIVE LEAD. A rule match records a pattern and its supporting events. It does not establish maliciousness, attribution, or causation.

Rule Library

No rules configured.

Rule Lead Review

Rule Editor

WHEN — all conditions

Test Results

Test a rule against the current project without creating leads.

Specialized Views

Focused projections of normalized evidence. These views do not create new evidence or alter source records.

FOCUSED VIEW. Inclusion is based on normalized fields and source text. Absence from a focused view does not mean an event is irrelevant.

Process Timeline

Focused Evidence

No matching events.

Process Relationships

Parent/child relationships derived from normalized source fields or explicit process-launch text.

No process relationships found.

Focused Detail

Select an item to inspect it or pivot back to the main timeline.

Comparison Mode

Compare two normalized-time periods. Results are descriptive observations, not anomaly or causation determinations.

Period A · Baseline / Before

Period B · Incident / After

DimensionValuePeriod APeriod BChangeObservation

Saved Views

Saved views capture search, simple filters, time window, lane mode, and nested advanced-filter groups.

No saved views.

Custom Tags

Performance Diagnostics

Live instrumentation for CHRONICLE's local large-dataset pipeline. Values describe this browser session; they are not evidence findings.

Memory pressure is within the current advisory threshold.

Event Store & Index

v1.0 persists normalized events and retained source text in IndexedDB when available. Active-project events are hydrated into memory for cross-source correlation and findings, while timeline DOM rendering remains virtualized.

Release Readiness Self-Check

Runs local structural checks against the active build and project. This does not modify evidence and is not a forensic validation of source truth.

Self-check has not run in this session.

Large Dataset Controls

Case Notes

Notes autosave with the investigation. Use event annotations when a statement must be explicitly classified as evidence, observation, inference, hypothesis, or conclusion.

Export Investigation

Exports are generated locally. Timeline CSV protects spreadsheet cells beginning with formula characters.

No evidence package generated in this session.

Evidence Integrity Manifest

CHRONICLE v1.0 hashes new imports from original file bytes before parsing. Evidence migrated from earlier releases is explicitly labeled legacy-decoded-text where the original byte hash is unavailable.
No evidence sources.

Audit Trail

Meaningful project actions only; routine navigation and display changes are intentionally omitted.

TimeActorCategoryActionObjectDetail

Export History

No exports recorded.

Local Data Controls