SHARED RECORDS ACROSS EVIDENCE PACKAGES

Case Correlation Desk

Drop files here

Open at least two evidence packages together.

Web Evidence Recorder and Sandbox ZIP packages, and JSON records, are read only in this browser. Files are not uploaded.

ZIP and JSON, up to 12 files
Matches mean the same technical value appears in more than one package. They do not establish identity, ownership, or attribution.

TECHNICAL ARCHITECTURE

Case correlation desk

Connects the relationships between event and entity records.

Download the PDF guidePDF · 2 pages
How does it work?Method, steps, and limits are in the PDF.
  1. Input

    Event and entity records

  2. Method

    Match shared observables with case context

  3. Human check

    Check the result against the source

  4. Output

    A relationship graph

ProcessingRuns locally in your browser