TraceSec turns a pile of endpoint and identity events into something an analyst can act on: what happened, why it matters, how sure we are, and what to do next. Every verdict is grounded in the evidence it cites, and every alert is weighed against what the environment normally does.
Paste events or drop an export file: a CSV from Defender Advanced Hunting, an Event Viewer export (XML or CSV), Sysmon or JSON, or plain text. Identities are replaced in your browser before anything is sent.
Results open as an investigation page and stay in this browser. Create an account to keep investigations, share them with your team and use the dashboard.
Three stages, each visible in the result. Nothing is a black box: the classification and the context are shown next to the verdict.
An analyst pastes the rows from Advanced Hunting or drops the export file. Timestamps, processes, parents, accounts, devices and addresses are extracted, and identities are replaced before anything is analyzed.
Thirty behavioral rules cover execution, persistence, credential access, lateral movement and impact. Context that argues for legitimacy, such as a deployment agent, a signed binary or fleet prevalence, counts just as much.
The findings become a case: summary, evidence with cited events, MITRE techniques, the false-positive balance, prioritized next steps and the queries to run. With Claude enabled, the explanation reads like a senior analyst wrote it.
Built for SOC teams and MSSPs that run on Microsoft Defender and need to explain verdicts to customers, not just produce them.
Expected, unusual and suspicious are separate buckets. An unusual event with a legitimate explanation never gets the same weight as a known technique.
Each finding cites the exact events, the technique and why it deviates from normal. Nothing in the verdict is unsourced.
Both sides of the evidence before a verdict, plus a scale from "likely legitimate" to "likely malicious" so a customer can see why a case was closed.
Every recommended step that needs data comes with the Advanced Hunting query, explained in one sentence.
Identities are pseudonymized in the browser and in every report. Multi-tenant by design, so one MSSP account serves many customers without mixing data.
The rule engine runs on its own and costs nothing per case. Claude's explanation is a per-tenant switch, and a self-hosted model can take its place.
Anonymous analyses stay in your browser. With an account, every investigation is stored for your tenant, shows up in the dashboard with status and assignee, and can be shared with your team.