Windows Event & Sysmon Log Parser
Paste Windows Event Log XML, Sysmon events, Winlogbeat JSON or CSV exports to get normalized actor, process, logon and outcome fields, an explainable risk score, MITRE ATT&CK mapping and ready-to-paste investigation notes — entirely in your browser.
Event input
Paste Event Viewer XML, Winlogbeat/Elastic JSON lines, CSV exports or plain Sysmon text. Everything is parsed locally in your browser — nothing is uploaded.
Examples:
Paste events or load an example to begin. Supported: Event Viewer XML, Winlogbeat/Elastic JSON lines, CSV, and plain Sysmon text.