Products/Cloud Investigation
Cloud Investigation
New

Fully autonomous forensic investigation

Upload your logs. Get the whole story.

Fully autonomous forensic investigation for your cloud and SaaS logs. Tell us what you suspect, and an AI investigator works through every file on its own to reconstruct what happened: who got in, how, what they touched, and whether they are still there.

Fully autonomous
Every file examined
Every finding re-checked
Uploads deleted after the run

Every file

Read before "nothing found" is allowed

2 AIs

One investigates, one re-checks the evidence

0 files

Kept after the run, only the report remains

Hours

Not the days it takes to read logs by hand

The finished investigation

What happened, how it happened, and what it found

Severity counts computed from the record, a plain-language account of the intrusion, an attack chain you can play back, and every finding with its evidence.

app.xhack.io / investigations / report

A completed Cloud Investigation: severity counts, a plain-language account of what happened, and the attack chain player

The problem

The answer is buried in tens of thousands of log lines

When an account is compromised, reading the logs by hand takes days. So most teams check the obvious sign-ins, reset a few passwords, and hope.

Attackers count on that.

By hand

Days of reading, and the one line that matters still gets missed.

The usual shortcut

Check sign-ins, reset passwords, close the ticket. The mail rule stays.

Cloud Investigation

Every file read, every lead followed, every finding backed by evidence.

What it can find

The whole incident, not just the sign-in

The AI reads every log, follows every lead, and reconstructs each stage of the attack.

How they got in

Stolen sessions, password spraying, phishing and MFA tampering.

What they did inside

Mailbox access, file downloads, searches for payment details.

How they spread

Internal phishing, compromised colleagues and admin accounts taken over.

How they stayed hidden

Mail rules that bury security alerts, deleted evidence, audit logging switched off.

How data left

Forwarding rules, transport rules and external sharing.

Persistence that survives cleanup

Access that outlasts a password reset, like rogue app permissions.

Whether they are still in

Activity after the point you thought the incident was over.

Signal, not noise

A failed login storm that achieved nothing is reported as exactly that, not mistaken for the breach.

How it works

From a pile of logs to a forensic report

You upload the logs. The AI reads every one of them and hands you the whole incident in plain language, backed by evidence.

1

Upload

Drop in audit logs as individual files or zipped bundles.

2

Describe

What you suspect, when you noticed, which accounts worry you, what you already did.

3

Investigate

The AI reads every file and follows every lead. Watch live or walk away.

4

Verify

A second, independent AI re-checks each finding against its evidence.

5

Report

A forensic report in plain language, as PDF or HTML.

app.xhack.io / investigations / new

Starting a new investigation: upload the logs, then describe what you think happened

Start an investigation

Tell it what you suspect, the way you would tell a colleague

Drop in zip archives or loose log files. Only a title is required. Everything else is a head start: it changes what gets looked at first, never what gets looked at. Every file is swept either way, and anything found outside what you suspected is still reported.

What do you think happened?

How serious does it look, and which cloud is it?

When did you notice, and which accounts worry you?

Have you already done anything about it? This stops your own response being read as the attacker.

Every finding is double-checked

Proved, or clearly marked as not

Each finding cites the evidence it rests on. A second, independent AI re-checks that evidence against the claim before it goes into your report.

If a finding does not fully hold up, it is marked Unverified, never quietly passed off as fact. You always know the difference between what was proved and what was suspected.

Nothing gets skipped. The investigation cannot report "nothing found" until it has examined every file. If a file could not be read, the report tells you so.

investigation / findings

Findings list: each finding shows its severity, a Verified badge and the MITRE ATT&CK techniques it maps to

Verified

evidence re-checked and holds

Unverified

did not fully reproduce

Dropped

suspicion ruled out

Watch it work, live

No spinner. Watch the investigation think.

Suspicions the AI later rules out stay visible, marked as dropped, so you can see exactly how it reached its conclusions.

Agent view

The AI reasoning as it happens, and each step it takes to test a theory.

Terminal view

Every search it runs, and exactly what came back.

Live progress

From reading the logs through to writing the report.

Fullscreen mode

Follow along in detail on a second screen.

From a real run

Each script the AI runs, how many rows it read, and the notes it takes as evidence turns up.

Agent view of a live investigation: scripts with rows read, and notes recording new inbox rules and a transport rule

What you get

A complete forensic report

Downloadable as PDF or HTML, ready to share with your team, leadership, insurer or legal counsel.

How it happened

The whole intrusion, in order, from the first moment

The report reconstructs the attack stage by stage and names the actor behind every step. It marks the first moment of the intrusion and keeps going past the point you thought it was over, so access that survived your remediation is not missed.

Play the chain back stage by stage, or read it as a timeline

Attacker actions and your own response shown apart

Every stage tied to the account or address behind it

Read a sample report (PDF)

investigation / how it happened

Attack timeline: fourteen stages from a password spray to access that continued after remediation

Executive summary written for leadership

Every finding with severity, evidence and the fix

Full attack timeline, step by step

Attacker profile: infrastructure and behaviour

Blast radius: accounts, mailboxes and data affected

Indicators of compromise ready to block

Prioritised remediation steps

An honest list of what could not be determined, and why

PDF
HTML
For your team
For leadership
For your insurer
For legal counsel

What it works with

Your logs, whatever shape they are in

Logs in unfamiliar formats are learned on the spot. The AI works out the structure itself.

Microsoft 365 and Entra ID

Unified audit log, sign-ins, Exchange and SharePoint activity.

AWS CloudTrail

API calls, console sign-ins and IAM changes.

Google Workspace

Admin, login, Drive and Gmail activity.

Firewall and network

Perimeter and flow logs from your network devices.

Server and SSH

Auth logs, sessions and command history.

Any common format

CSV, JSON, JSON Lines, key-value and plain text.

What you can do

In control from upload to report

Upload logs as individual files or zipped bundles

Describe the incident in your own words

Watch the investigation live, or walk away

Get an email when it is done

Cancel a run at any time

Rate each finding and add notes for your team

Download the report as PDF or HTML

Send notifications into your own tools by webhook

Who it is for

Answers in hours, not days

Security teams

Who need answers in hours, not days.

IT administrators

Handling a suspected account takeover without a dedicated SOC.

MSPs and consultants

Running incident response for their clients.

Leadership, insurance, legal

Anyone who needs a clear, evidence-backed account of what happened.

Your data stays yours

Built to handle evidence carefully

Incident logs are some of the most sensitive data you have. The platform treats them that way.

Isolated per run

Every investigation runs in its own environment, created for that run and destroyed when it ends.

Uploads deleted

Your files are deleted as soon as the investigation finishes, whatever the outcome. Only the report and its findings are kept.

Private to your workspace

Investigations are visible only inside your own workspace.

Logs cannot steer it

Text an attacker planted in your logs is treated as evidence, never as instructions.

Availability

Included on your plan

Cloud Investigation ships with the researcher and company plans below.

Researcher plans

Professional
Elite

Company plans

Starter
Premium
Elite

Usage limits apply and vary by plan

Compare plans

FAQ

Questions teams ask first

It reads every file you upload, forms theories about what happened, and tests each one by searching the evidence, the same way a human investigator would, only across every line. You can watch that reasoning and every search it runs, live.

Every finding cites the evidence it rests on, and a second, independent AI re-checks that evidence against the claim before it reaches your report. If a finding does not fully hold up, it is marked Unverified. You always know what was proved and what was only suspected.

The investigation cannot report "nothing found" until it has examined every file you uploaded. If a file cannot be read, for example an image or an unsupported format, the report says so rather than silently skipping it.

Logs in unfamiliar formats are learned on the spot. The AI works out the structure itself, so you do not have to convert anything before uploading.

No. Log content is treated strictly as evidence, never as instructions. Text an attacker planted in your logs cannot steer the investigation.

Each investigation runs in its own isolated environment, created for that run and destroyed when it ends. Your uploaded files are deleted as soon as the investigation finishes, whatever the outcome. Only the report and its findings are kept, and they are private to your workspace.

Researcher Professional and Researcher Elite, and every company plan: Starter, Premium and Elite. Usage limits apply and vary by plan. If you need more capacity, talk to us.

Upload your logs. Get the whole story.

Who got in, how, what they touched, and whether they are still there, with the evidence to prove it.