Cybersecurity · free, no signup
Incident Timeline Builder
Paste log lines from different systems and get one ordered timeline, with every assumption it had to make written on the events it touched. Timestamps are the hard part of any incident: half the sources omit a zone, some print local time, some print an instant, and ordering them as though they were comparable is how reconstructions go wrong. An ambiguous date is reported as ambiguous rather than resolved by guessing, a day the calendar does not contain is refused rather than rolled forward, and credential-shaped values in the log are named but never quoted back.
Authorized, defensive use only. Check assets you own or lawfully public data. This tool is educational and never provides another party's private data.
Paste log lines from different systems and get one ordered timeline, with every assumption it had to make written onto the events it touched. Timestamps are the hard part: half the sources omit a zone, some print local time, some print an instant, and ordering them as if they were comparable is how reconstructions go wrong.
An ambiguous date is reported as ambiguous rather than resolved by guessing, and a day the calendar does not contain is refused rather than rolled forward. Credential-shaped values in the log are named but never quoted back to you.
What happens to what you enter
- The analysis runs on Solvex servers. What is recorded afterwards is a SHA-256 hash of your input and a coarse summary of the outcome — never the input itself, and never a result you could be identified from.
- Tools that read public sources (certificate logs, DNS, a public chain) contact those sources from our servers through a fetcher that refuses private and internal addresses.
- An email address is stored only where a tool offers to send you a report and you choose to give one.
Limits: ten runs of this tool per minute from one address, and three signed reports per minute. Past that the tool says so and tells you when to try again.
When a free check is not enough
This tool reads what is public and reports what it can see. The 24/7 Incident Response Retainer engagement is the authorized, specialist-led version: signed scope, findings proven by hand, a signed report, and a retest.
Explore 24/7 Incident Response Retainer