PastePile

Evidence formats

Windows Event Log (EVTX) analysis

Drop the .evtx files from an affected host into a case. PastePile parses Security, System and Sysmon channels, normalizes each record, and runs its Windows compromise pack over the result. Each case gets a timeline, findings that cite the exact records behind them, a list of what the evidence cannot establish, and hunts compiled to Defender KQL, Sentinel KQL, Splunk SPL, Elastic ES|QL and Sigma for the tools you already run.

What you can upload

  • Native Windows Event Log files (.evtx), including Sysmon
  • Windows System/EventData JSON or JSONL, including compatible Velociraptor event-log output
  • Hayabusa standard-field timelines (CSV, JSON or JSONL); its rule matches are kept as imported claims, not PastePile findings

What PastePile checks

  • Office applications or browsers spawning script interpreters
  • Encoded PowerShell, with the payload decoded where it can be, and PowerShell downloads
  • Suspicious use of built-in binaries (LOLBins), including certutil decoding or downloading a file
  • Persistence: scheduled tasks, new services, services installed from user-writable paths, and Run keys that launch a script interpreter
  • Account creation and additions to privileged groups
  • Security event log cleared, Defender exclusions added, shadow copies deleted and recovery disabled with bcdedit
  • Remote process creation with wmic
  • Rare parent/child process pairs and first-seen external destinations, reported as rarity within your upload, never as findings

Every finding cites the records behind it and states what it does not establish. Statistical signals are reported as rarity within your upload and never become findings. ATT&CK mappings describe what a behavior resembles, not proof that an adversary was present.

What it does not do

  • No memory, disk image or live endpoint collection
  • ZIP collections are refused; upload the .evtx files themselves
  • A finding says what the records support; it is not a verdict that the host is or is not compromised

Try it

Open the synthetic Office document to encoded PowerShell case to see the timeline, findings, unknowns and report without an account. When you are ready, create an account and compare plans.

Other evidence formats