Introduction
Corelog is a forensic investigation tool for Microsoft 365 audit logs. You give it a Microsoft Purview Audit Search CSV export; it gives you an interactive investigation interface over that activity — an activity matrix, thirteen MITRE ATT&CK-mapped anomaly detections, geolocation down to the city and the network operator, a presence analysis against the networks your organisation recognises, and an exportable audit report.
It is free, requires no account, and runs entirely inside your browser tab.
What you need
Section titled “What you need”One thing: a CSV export from Microsoft Purview Audit Search. See Exporting from Purview for how to produce one.
Corelog reads these columns:
RecordId, CreationDate, RecordType, Operation, UserId, AuditData,AssociatedAdminUnits, AssociatedAdminUnitsNamesAuditData is a stringified JSON blob whose shape varies by RecordType. Corelog parses
it defensively — missing fields are fine, and operations it has never seen fall back to a
category derived from the operation name rather than being discarded.
File size limit: 1 GB. Parsing runs in a Web Worker so the interface stays responsive.
What it does not do
Section titled “What it does not do”- It does not upload your file. Analysis happens in the tab. See Privacy.
- It does not replace an investigation. Every detection is a heuristic: it produces false positives and misses real activity. Detections are an aid to an analyst, not a verdict.
- It does not keep anything. Close the tab and the data is gone. There is no account, no case history and no persistence of anything derived from your CSV.
How to read a detection
Section titled “How to read a detection”Every detection publishes its exact criteria — the count, the time window, the baseline it compares against and the MITRE ATT&CK technique it maps to. This is deliberate: if a tool flags an event, you should be able to state precisely why to a client, an auditor or a court. A score you cannot decompose is not a finding.
Two properties are worth knowing before you interpret any result:
Location comes from the IP, not from Purview’s GeoLocation field. That field is a
multi-geo datacenter region on most tenants, not a country. See
Geolocation.
“Nothing found” and “we could not look” are different answers. Where a dataset is too short or too sparse to support an analysis, Corelog says so rather than returning an empty result that reads like an all-clear. The audit report carries this the furthest: it has a whole section for questions it examined and found clear, with a third verdict for the ones your export cannot answer at all.
Not every event was caused by a person. Roughly two thirds of a typical export is written by the platform itself — a mail client synchronising, an attachment opened for indexing. Corelog tells the two apart by operation, because the address cannot: most background mail access arrives from the user’s own network. See Interactive and automatic activity.
- Exporting from Purview — producing the input file
- Detection reference — exact criteria for all thirteen detections
- Behavior shifts — the statistical layer that runs alongside them
- Interactive and automatic activity — which events a person actually caused
- Addresses and networks — where activity came from, and declaring your own networks
- Presence — time against the networks the organisation recognises
- The audit report — what the exported PDF and Markdown contain