Skip to content
All Docs

Artifact, Manual Review, and Timeline Guide

Artifact, Manual Review, and Timeline Guide#

AI analysis is the fast starting point. Artifact viewer, manual review, and timeline analysis are the verification tools that help you inspect source context and reconstruct what happened.

Role of Each Surface#

FeatureRoleWhat to Check
Artifact ViewerBrowse parsed evidence by typeOriginal path, time, user, hash, metadata
Manual ReviewSearch and filter evidence directlySpecific time window, file, artifact type
Timeline AnalysisConnect events chronologicallyExecution, access, connection, deletion, upload order
AI AnalysisSearch evidence and generate natural-language answersSummary, correlation, next investigation direction
  1. Ask a broad AI question to find suspicious areas.
  2. Open cited evidence in the artifact viewer.
  3. Search nearby user, file, and time context in manual review.
  4. Reconstruct before-and-after activity in the timeline.
  5. Include only verified evidence in reports and label inference separately.

Timeline Review Points#

  • Activity concentrated outside normal hours
  • File access or archive creation after USB connection
  • Privilege changes or remote login after account creation
  • Autorun registration or outbound network activity after suspicious execution
  • Deletion events followed by log gaps or cleanup traces

Manual Review Filter Examples#

Investigation GoalFilter Ideas
USB exfiltrationUSB, Shellbags, RecentDocs, LNK, file access times
Malware executionPrefetch, AmCache, Shimcache, EventLog, autoruns
Account compromiseLogon events, account changes, remote access, privilege changes
Cloud leakageBrowser history, downloads, cache, sync logs, archives
AI usage tracesBrowser AI services, coding tools, project changes, downloaded files

Practical Tips#

  • Use timeline for ordering, not final judgment alone.
  • Use manual review when AI found a lead but you need exact fields.
  • Lower confidence if path, user, or time context does not match.
  • Confidence improves when multiple artifact types point to the same time and action.

Next Steps#

Continue in the service

Move from this guide into a sample workflow or the relevant upload surface. Upload real evidence only when you have lawful authority.