Preserve and trace
Keep imported source context visible while derived analysis remains explainable.
PRODUCT
EVIDRYN helps SOC and DFIR analysts transform exported Wazuh alerts into evidence-led investigations, historical context and practical verification guidance.
THE INVESTIGATION GAP
Exported SIEM alerts often leave analysts reconstructing evidence, pivots and prior history by hand. EVIDRYN creates a consistent local investigation workspace without taking authority away from the analyst.
Keep imported source context visible while derived analysis remains explainable.
Surface observed IPs, domains, URLs, hashes, filenames and related context when present.
Connect triage, timeline, graph, MITRE ATT&CK and Living Off the Land context.
Compare current evidence with eligible prior cases using deterministic similarity scoring.
Show display-only telemetry pivots and starter queries that analysts adapt and run themselves.
Record analyst verdicts, generate structured reports and verify local backups and restores.
VERIFIED PILOT CAPABILITIES

EVIDRYN structures evidence and provides decision support. It does not execute Guide queries, change source alerts, contain endpoints or make the final verdict.
Cases remain in an explicit customer-controlled workspace. The pilot runs on localhost and has no public SaaS or live SIEM connection.
CURRENT WAZUH COMPATIBILITY
EVIDRYN accepts authorized Wazuh JSON, JSON-array and NDJSON exports. Dry-run preview, bounded handling, stable source identity and duplicate prevention support a controlled pilot workflow.