Skip to content
All Docs

Support Scope Matrix

Support Scope Matrix#

This page helps users decide whether their evidence source is a good fit for unJaena AI. It intentionally avoids internal parser implementation, search ranking, private detection rules, prompts, and server-side profile logic.

How to Read Support Counts#

unJaena AI uses 650+ supported artifact definitions to guide collection, parsing, indexing, and evidence search. That count is not internal source code, and it does not mean every artifact is always collected in every environment. Actual case coverage depends on the operating system, installed applications, permissions, user consent, collection profile, and the quality of uploaded evidence.

This matrix is written at a public customer-facing level so teams can judge fit before using the service. Internal parser priority, server validation behavior, private detection rules, prompts, and search ranking weights are intentionally not published for service security and anti-evasion reasons.

Sources and Input Methods#

SourceInput MethodMain SurfacesWhat You Can ReviewKey Limits
WindowsCollector live collection, uploaded filesAI analysis, manual review, timeline, reportExecution traces, event logs, registry, USB, browser, user activityAdministrator and lawful authority required
macOSCollector live collection, uploaded filesAI analysis, manual review, timeline, reportUnified Log, FSEvents, Spotlight, Safari, TCC, user activityScope depends on Full Disk Access and OS policy
LinuxCollector live collection, uploaded filesAI analysis, manual review, timeline, reportsyslog, journald, auth logs, shell history, SSH, browser tracesDistribution and privilege level affect coverage
iOSUSB direct collection, backup files, extracted artifactsAI analysis, manual review, timeline, reportMessages, calls, contacts, Safari, location, app data, media metadataTrust pairing, backup password, and iOS policy affect scope
AndroidUSB direct collection, extracted artifactsAI analysis, manual review, timeline, reportSMS, calls, contacts, app list, browser, Wi-Fi, device settingsUSB debugging, rooting, and app sandboxing affect scope
OpenText EnCaseEnScript selected-entry uploadAI analysis, manual review, timeline, reportSelected evidence entries and metadata from an EnCase caseDoes not replace EnCase acquisition or examiner validation
General filesWeb uploadArtifact viewer, AI analysis, reportDocuments, logs, archives, extracted evidence bundlesParser support depends on format
Malware samplesMalware Lab uploadOverview, YARA, behavior, graph, AI analysis, Q&A, reportFile risk, capabilities, IOCs, MITRE mapping, code and behavior summaryPrivate rule text and scoring formulas are not disclosed
ContractsContract review uploadContract analysis reportClause-level risks, obligations, termination, liability, jurisdiction hintsInformation analysis only, not legal advice

Analysis Surfaces#

SurfacePurposeBest Fit
AI AnalysisNatural-language evidence search and synthesisIncident traces, exfiltration, insider risk, AI usage traces
Manual ReviewDirect artifact filtering and reviewVerifying AI answers, checking a file, log, or time range
Timeline AnalysisOrdering events over timeInfection flow, USB-before-after activity, account changes
Artifact ViewerInspect parsed evidence itemsOpening cited evidence and checking original context
Integrated ReportShare investigation outputInternal reporting, client reporting, follow-up direction
Malware TabsInterpret sample structure, behavior, and IOCsSuspicious-file triage, IOC extraction, case linkage
Contract AnalysisReview contract clauses for information risksPre-signature review and obligation mapping

Not Published Here#

  • Internal parser code and mapping logic
  • Chimborazo search strategy, ranking weights, and full prompts
  • Private YARA rule text or bypass-relevant detection details
  • Server API headers, token validation details, and internal paths
  • Queue, database, infrastructure, and operational security details

Next Steps#

Continue in the service

Move from this guide into a sample workflow or the relevant upload surface. Upload real evidence only when you have lawful authority.