✓99 Windows events, sourced
Security, Sysmon, System, Application, and PowerShell — every event with a monitoring call and why.
✓NIST 800-53 mapping
34 controls tied to exact event codes, plus an Evidence Builder for audit prep.
✓MITRE ATT&CK coverage
30 techniques mapped, with gaps named honestly instead of glossed over.
✓MITRE ATLAS coverage
The AI/ML threat framework — 6 techniques where Windows logging genuinely helps, honest about the rest.
✓CIS Controls coverage
Controls 5 & 8 mapped to real event evidence — only 6 of 18 safeguards are actually log-provable, named honestly.
✓PCI DSS Requirement 10 coverage
All 7 event-logging sub-requirements of 10.2.1 mapped to real event evidence — the tightest hit rate of any framework on this site.
✓DISA STIG coverage
Windows Server 2022 STIG V2R4 audit-policy rules mapped to event evidence, cross-referenced to NIST 800-53 through each rule's own CCI.
✓Live policy scanner
Upload real audit policy, Sysmon, and PowerShell configs — see what's actually covered.
✓Gap analyzer with one-click fixes
Pick a technique, see exactly what's missing, fix it instantly.
✓Dependency graph
Policy → event → framework coverage, visualized as one connected map.
✓SIEM cost optimizer
Keep / Filter / Sample / Drop guidance, tuned to Splunk, Sentinel, and others.
✓Runs entirely in your browser
Nothing uploaded, no server. Dark or light mode.