Fully autonomous forensic investigation
Upload your logs. Get the whole story.
Fully autonomous forensic investigation for your cloud and SaaS logs. Tell us what you suspect, and an AI investigator works through every file on its own to reconstruct what happened: who got in, how, what they touched, and whether they are still there.
Every file
Read before "nothing found" is allowed
2 AIs
One investigates, one re-checks the evidence
0 files
Kept after the run, only the report remains
Hours
Not the days it takes to read logs by hand
The finished investigation
What happened, how it happened, and what it found
Severity counts computed from the record, a plain-language account of the intrusion, an attack chain you can play back, and every finding with its evidence.
app.xhack.io / investigations / report

The problem
The answer is buried in tens of thousands of log lines
When an account is compromised, reading the logs by hand takes days. So most teams check the obvious sign-ins, reset a few passwords, and hope.
Attackers count on that.
By hand
Days of reading, and the one line that matters still gets missed.
The usual shortcut
Check sign-ins, reset passwords, close the ticket. The mail rule stays.
Cloud Investigation
Every file read, every lead followed, every finding backed by evidence.
What it can find
The whole incident, not just the sign-in
The AI reads every log, follows every lead, and reconstructs each stage of the attack.
How they got in
Stolen sessions, password spraying, phishing and MFA tampering.
What they did inside
Mailbox access, file downloads, searches for payment details.
How they spread
Internal phishing, compromised colleagues and admin accounts taken over.
How they stayed hidden
Mail rules that bury security alerts, deleted evidence, audit logging switched off.
How data left
Forwarding rules, transport rules and external sharing.
Persistence that survives cleanup
Access that outlasts a password reset, like rogue app permissions.
Whether they are still in
Activity after the point you thought the incident was over.
Signal, not noise
A failed login storm that achieved nothing is reported as exactly that, not mistaken for the breach.
How it works
From a pile of logs to a forensic report
You upload the logs. The AI reads every one of them and hands you the whole incident in plain language, backed by evidence.
Upload
Drop in audit logs as individual files or zipped bundles.
Describe
What you suspect, when you noticed, which accounts worry you, what you already did.
Investigate
The AI reads every file and follows every lead. Watch live or walk away.
Verify
A second, independent AI re-checks each finding against its evidence.
Report
A forensic report in plain language, as PDF or HTML.
app.xhack.io / investigations / new

Start an investigation
Tell it what you suspect, the way you would tell a colleague
Drop in zip archives or loose log files. Only a title is required. Everything else is a head start: it changes what gets looked at first, never what gets looked at. Every file is swept either way, and anything found outside what you suspected is still reported.
What do you think happened?
How serious does it look, and which cloud is it?
When did you notice, and which accounts worry you?
Have you already done anything about it? This stops your own response being read as the attacker.
Every finding is double-checked
Proved, or clearly marked as not
Each finding cites the evidence it rests on. A second, independent AI re-checks that evidence against the claim before it goes into your report.
If a finding does not fully hold up, it is marked Unverified, never quietly passed off as fact. You always know the difference between what was proved and what was suspected.
Nothing gets skipped. The investigation cannot report "nothing found" until it has examined every file. If a file could not be read, the report tells you so.
investigation / findings

Verified
evidence re-checked and holds
Unverified
did not fully reproduce
Dropped
suspicion ruled out
Watch it work, live
No spinner. Watch the investigation think.
Suspicions the AI later rules out stay visible, marked as dropped, so you can see exactly how it reached its conclusions.
Agent view
The AI reasoning as it happens, and each step it takes to test a theory.
Terminal view
Every search it runs, and exactly what came back.
Live progress
From reading the logs through to writing the report.
Fullscreen mode
Follow along in detail on a second screen.
From a real run
Each script the AI runs, how many rows it read, and the notes it takes as evidence turns up.

What you get
A complete forensic report
Downloadable as PDF or HTML, ready to share with your team, leadership, insurer or legal counsel.
How it happened
The whole intrusion, in order, from the first moment
The report reconstructs the attack stage by stage and names the actor behind every step. It marks the first moment of the intrusion and keeps going past the point you thought it was over, so access that survived your remediation is not missed.
Play the chain back stage by stage, or read it as a timeline
Attacker actions and your own response shown apart
Every stage tied to the account or address behind it
investigation / how it happened

Executive summary written for leadership
Every finding with severity, evidence and the fix
Full attack timeline, step by step
Attacker profile: infrastructure and behaviour
Blast radius: accounts, mailboxes and data affected
Indicators of compromise ready to block
Prioritised remediation steps
An honest list of what could not be determined, and why
What it works with
Your logs, whatever shape they are in
Logs in unfamiliar formats are learned on the spot. The AI works out the structure itself.
Microsoft 365 and Entra ID
Unified audit log, sign-ins, Exchange and SharePoint activity.
AWS CloudTrail
API calls, console sign-ins and IAM changes.
Google Workspace
Admin, login, Drive and Gmail activity.
Firewall and network
Perimeter and flow logs from your network devices.
Server and SSH
Auth logs, sessions and command history.
Any common format
CSV, JSON, JSON Lines, key-value and plain text.
What you can do
In control from upload to report
Upload logs as individual files or zipped bundles
Describe the incident in your own words
Watch the investigation live, or walk away
Get an email when it is done
Cancel a run at any time
Rate each finding and add notes for your team
Download the report as PDF or HTML
Send notifications into your own tools by webhook
Who it is for
Answers in hours, not days
Security teams
Who need answers in hours, not days.
IT administrators
Handling a suspected account takeover without a dedicated SOC.
MSPs and consultants
Running incident response for their clients.
Leadership, insurance, legal
Anyone who needs a clear, evidence-backed account of what happened.
Your data stays yours
Built to handle evidence carefully
Incident logs are some of the most sensitive data you have. The platform treats them that way.
Isolated per run
Every investigation runs in its own environment, created for that run and destroyed when it ends.
Uploads deleted
Your files are deleted as soon as the investigation finishes, whatever the outcome. Only the report and its findings are kept.
Private to your workspace
Investigations are visible only inside your own workspace.
Logs cannot steer it
Text an attacker planted in your logs is treated as evidence, never as instructions.
Availability
Included on your plan
Cloud Investigation ships with the researcher and company plans below.
Researcher plans
Company plans
Usage limits apply and vary by plan
FAQ
Questions teams ask first
It reads every file you upload, forms theories about what happened, and tests each one by searching the evidence, the same way a human investigator would, only across every line. You can watch that reasoning and every search it runs, live.
Every finding cites the evidence it rests on, and a second, independent AI re-checks that evidence against the claim before it reaches your report. If a finding does not fully hold up, it is marked Unverified. You always know what was proved and what was only suspected.
The investigation cannot report "nothing found" until it has examined every file you uploaded. If a file cannot be read, for example an image or an unsupported format, the report says so rather than silently skipping it.
Logs in unfamiliar formats are learned on the spot. The AI works out the structure itself, so you do not have to convert anything before uploading.
No. Log content is treated strictly as evidence, never as instructions. Text an attacker planted in your logs cannot steer the investigation.
Each investigation runs in its own isolated environment, created for that run and destroyed when it ends. Your uploaded files are deleted as soon as the investigation finishes, whatever the outcome. Only the report and its findings are kept, and they are private to your workspace.
Researcher Professional and Researcher Elite, and every company plan: Starter, Premium and Elite. Usage limits apply and vary by plan. If you need more capacity, talk to us.
Upload your logs. Get the whole story.
Who got in, how, what they touched, and whether they are still there, with the evidence to prove it.
