Decision supported.
Builds an evidence source matrix and investigation sequence for a selected incident scenario.
Intended user
research, assurance and technical review teams
Builds an evidence source matrix and investigation sequence for a selected incident scenario.
Builds an evidence source matrix and investigation sequence for a selected incident scenario.
research, assurance and technical review teams
Data handling: this interface uses the L2ET protected same-origin instrument engine. Do not enter confidential, regulated, privileged, incident, medical or sensitive operational data.
Maps incident type to evidence families, prioritizes volatile and high-value sources, and converts log coverage and time-window uncertainty into preservation priority.
Use the controls below to generate a preliminary artifact. The output is intentionally bounded and requires human review.
The generated artifact includes findings, assumptions, limitations, recommended next actions and exportable structured output.
Cloud account compromise with hybrid environment, partial logs and broad time window.
Outputs evidence matrix covering identity logs, cloud audit, endpoint telemetry, email logs, timeline plan and chain-of-custody reminders.
This instrument does not provide legal, medical, cryptographic, engineering, regulatory or compliance certification.
Read the family method note for assumptions, output artifacts, update policy and review boundaries.