PastePile

Product

Evidence you can analyze

Windows event logs, Sysmon, Defender exports, Entra sign-ins and suspicious email. Each format below says what PastePile accepts, what it checks, and what it does not claim.

Windows Event Log (EVTX) analysis

Upload Windows EVTX files, including Security, System and Sysmon channels, and get a timeline, cited findings and hunt queries for persistence, encoded PowerShell and log clearing.

Sysmon log analysis

Analyze Sysmon event logs for process creation, network connections and registry changes. Get cited findings, a timeline and hunt queries in KQL, SPL, ES|QL and Sigma.

Microsoft Entra sign-in log analysis

Upload Entra ID sign-in logs as CSV or JSON. Error codes are mapped to their documented meaning; many accounts tried from one source, failures then a success, and new privileged roles are flagged with the records cited.

Microsoft Defender for Endpoint export analysis

Analyze Microsoft Defender for Endpoint advanced hunting exports (CSV or JSON). Events are mapped by ActionType into a timeline with cited findings and hunts to run back in Defender.

Phishing email and header analysis

Paste email headers or upload an .eml file. SPF, DKIM and DMARC failures, reply-to mismatches, display-name impersonation, lookalike domains, risky links and attachments are flagged without contacting any link.

Every format lands in the same case, on one timeline. See how it works, explore a synthetic demo case without an account, or compare plans.