What reaches us, and what doesn't
- Your files stay in your browser. Only the fields Jev needs are sent, one process at a time, through this site's relay to TypeSafe. Browsers can't call TypeSafe directly, so the relay forwards each request as-is and keeps nothing.
- Demo key or yours. The demo uses our TypeSafe key, on the bundled lab example only. Your own key is passed along with each request and never stored or logged.
- OpenRouter goes direct. Your OpenRouter key goes straight from this browser to
openrouter.ai. The page can't connect anywhere else; read the code.
Source events
JSON · 1–500 events · 2 MiB maxDrop a JSON export hereProcess, file, network or registry events
No events loaded
Actions
Offline preview ready
Jev access and API keys
Saved in this browser's local storage only. Leave unchecked on shared computers.Importing stays in this browser. Analyze sends selected fields of the seed, each candidate and nearby events through this site's relay to TypeSafe; a narrative is a separate opt-in sent directly to OpenRouter. Jev scores are relatedness, not maliciousness.
Results
Jev assessment
No Jev decisions. Local preview does not assign relatedness.
Narrative draft
Narrative is optional and must be requested separately.
Event timeline
0 linked eventsConfirmed seed: your confirmation, not a Jev scoreJev-linked execution: relatedness, not a malware verdictSame process: exact host and entity match, not Jev-scored
No linked events yet. Import source events, confirm a starting execution and analyze with Jev to build this sequence.
Timestamps are shown as supplied; valid times are normalized only for ordering.
Execution chain
No execution chain yet. Analyze with Jev to build the process chain; a narrative adds an AI-drafted version with ATT&CK mapping.
Process-to-process flow in time order. [evt:ID] links open the event in the timeline.
Evidence table
0 rowsLoad an export to begin.
| Timestamp | Host | Phase | Title | Description | Tools | TTPs | Command Line | Indicator | Type | Pyramid |
|---|