Defensive security workspace

BlueTeam Toolkits.

The open defender workspace. Turn events, indicators, and exposures into evidence you can act on.

Log parsing stays in your browser. Live lookups contact public data sources.

Local log parsing Explainable detection Public intelligence feeds

01 / Investigation preview

From raw event to a clear signal.

The same deterministic analysis used by the Windows Event & Sysmon parser.

01 — Raw event stream
Preparing sample…
02 — Analyst view
—/ 100

Analyzing · — events

Analyzing event pattern…

Open Windows Event parser

02 / Tool directory

Tools for the work at hand.

Go straight from an investigation question to the right analysis.

03 / Quick starts

Follow the evidence.

01

Suspicious email

Trace delivery, extract indicators, and investigate the source.

02

Endpoint alert

Understand the host event, then unpack suspicious content.

03

Vulnerability triage

Check confirmed exploitation and exploit likelihood before patching.