Corelog
Forensic investigation for Microsoft 365 audit logs. Free, no account, runs entirely in your browser.
Twelve MITRE ATT&CK-mapped detections with their full criteria, the behaviour-shift method, and how geolocation is resolved.
Documentation for Stratum Labs security analytics tooling.
These pages exist for one reason: every detection our tools make should be something you can explain. Each entry states its exact threshold, its time window, the baseline it compares against and the MITRE ATT&CK technique it maps to — so a finding survives the question “why did it flag that?”
Corelog
Forensic investigation for Microsoft 365 audit logs. Free, no account, runs entirely in your browser.
Twelve MITRE ATT&CK-mapped detections with their full criteria, the behaviour-shift method, and how geolocation is resolved.
Coming soon
A second product is in development. Its documentation will appear here alongside Corelog’s.