Observed arrival · 2026-09-30
Azure Forensics, in your browser
A free browser-based tool for triaging exported Azure logs for signs of a subscription compromise.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- Azure administrators investigating suspected subscription compromise
- Worth noticing
- The collection guide warns that portal CSV exports drop caller IPs and some diagnostic logs may not exist unless enabled before the incident.
Field notes
The collection walkthrough shows a Cloud Shell route: export Activity Logs for enabled subscriptions, optionally retrieve Defender for Cloud alerts, then zip the files for analysis. It also accepts folders and compressed exports, including .gz files. The page cautions that Activity Log retention is limited to 90 days, diagnostic logs depend on earlier settings, and some export paths can omit caller IPs or return only partial results.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central
One card from the complete issue