Incident Response Workspace

Run an incident from first alert to lessons learned in one place - severity, timeline, evidence hashes, indicators, actions, communications and chain of custody - saved locally and exported when you are ready.

Runs locally

Everything happens in your browser. What you paste or drop here is never uploaded, logged or stored.

Use the tool

One place for the whole incident

From the first alert to the post-incident review, the workspace keeps together what responders usually scatter across chat, spreadsheets and notes:

  • severity and status;
  • key times (detected, aware, contained, closed);
  • scope and impact;
  • a sorted timeline;
  • evidence with SHA-256 hashes and a chain-of-custody log;
  • indicators;
  • action items;
  • a communications log;
  • lessons learned.

Timeline entries can be imported from CSV, including the exports of the log analyzers on this site. Indicators can be extracted from pasted alert text.

Nothing leaves this tab unless you export it

By default nothing is saved: the incident lives in this tab's memory and disappears when you close it, so export before you leave. If you choose to keep it on this device, it is stored in this browser's local storage, readable by anyone with access to this browser profile. It is never sent to our server or anyone else. Erase everything removes it completely. Evidence files are hashed in your browser: the file is read to compute its SHA-256 and is neither kept nor uploaded. Only its name, size and hash are recorded.

Regulatory clocks

Enter when you became aware, and the Deadlines tab shows the notification clocks that commonly apply:

  • GDPR's 72 hours;
  • NIS2's 24-hour early warning, 72-hour notification and one-month final report;
  • DORA;
  • the SEC's four business days from a materiality determination;
  • HIPAA;
  • India CERT-In's six hours.

These are reminders, not legal advice. Whether a regime applies, and exactly when its clock starts, depends on your organisation and the facts, so confirm with counsel.

Frequently asked questions

Can several people work on the same incident?

Not live - there is no server. Share the exported JSON through your incident channel; anyone can import it, add to it and export again. The file carries its own timeline and custody log.

Why are indicators defanged in the report?

So links and addresses in the report cannot be clicked or auto-fetched by mail clients and chat tools. The JSON export keeps the original values.

Is the SHA-256 hash enough for chain of custody?

It proves a file has not changed since it was hashed. Chain of custody also needs who handled it, when and why - which is what the custody log records. Follow your legal team's evidence procedures for anything that may go to court.

References

What this tool can and cannot tell you. It reports what is present in the input you provide. It cannot see anything you did not give it, and a clean result means nothing was found in that input - not that the wider system is secure.

Security guidance here follows current published sources - OWASP, MDN, the relevant RFCs, NIST, CISA, FIRST and MITRE - which are linked beside the specific claims they support.

Rate this tool

Was this tool useful? Your feedback helps us improve it.

No ratings yet — be the first to rate this tool.
Your rating (required)
0 / 2000

Please do not include passwords, payment details or other sensitive information.

Your feedback is sent privately to the A2Z.Tools team and will not be posted publicly.