PRODUCT

Structured investigation. Preserved authority.

EVIDRYN helps SOC and DFIR analysts transform exported Wazuh alerts into evidence-led investigations, historical context and practical verification guidance.

THE INVESTIGATION GAP

Alerts arrive. Context does not.

Exported SIEM alerts often leave analysts reconstructing evidence, pivots and prior history by hand. EVIDRYN creates a consistent local investigation workspace without taking authority away from the analyst.

Evidence

Preserve and trace

Keep imported source context visible while derived analysis remains explainable.

Indicators

Extract useful IOCs

Surface observed IPs, domains, URLs, hashes, filenames and related context when present.

Investigation

Build a coherent view

Connect triage, timeline, graph, MITRE ATT&CK and Living Off the Land context.

Memory

Recall related history

Compare current evidence with eligible prior cases using deterministic similarity scoring.

Guide

Prepare verification pivots

Show display-only telemetry pivots and starter queries that analysts adapt and run themselves.

Operations

Report and preserve

Record analyst verdicts, generate structured reports and verify local backups and restores.

VERIFIED PILOT CAPABILITIES

One evidence-led workspace

  • Manual Wazuh JSON and NDJSON import
  • Evidence preservation, deduplication and provenance
  • Explainable triage, IOC extraction, timeline and graph
  • MITRE ATT&CK and Living Off the Land context
  • Case Memory and EVIDRYN Guide
  • Analyst verdicts, reports and verified backup/restore
EVIDRYN Pilot dashboard showing a synthetic PowerShell investigation
Real EVIDRYN Pilot 0.2.0 interface using synthetic demonstration data.

Analyst authority is the boundary

EVIDRYN structures evidence and provides decision support. It does not execute Guide queries, change source alerts, contain endpoints or make the final verdict.

Local-first by design

Cases remain in an explicit customer-controlled workspace. The pilot runs on localhost and has no public SaaS or live SIEM connection.

CURRENT WAZUH COMPATIBILITY

Controlled file import, not a live connector

EVIDRYN accepts authorized Wazuh JSON, JSON-array and NDJSON exports. Dry-run preview, bounded handling, stable source identity and duplicate prevention support a controlled pilot workflow.

What EVIDRYN does not do

  • No live polling, webhook or Wazuh writeback
  • No autonomous verdict, containment or incident closure
  • No public hosting, enterprise SSO or multi-tenant SaaS
  • No guaranteed detection or performance claim