Jev in production › Search, ranking and matching

Jevline

Jev scores how related processes, accounts and hosts are to one confirmed-malicious indicator, expanding it into a full incident timeline for analysts.

Open on GitHub ↗

The source publishes no measured number.
Use
Search, ranking and matching
Industry
Security
Form
Open-source tool
Stage
Announced
Listed
2026-10-07
Found via
github
Repository
tsale/jevline
Stars
37
Forks
4
Last push
2026-10-09
Language
TypeScript
License
MIT

The README opens with

Start from one process, address, account or host you know is malicious. Get back the incident.

Once an analyst confirms one malicious process, the next question is always what else is part of this?

Jevline follows every link the telemetry records out of it: - between processes: children, code injection, files dropped and then run, persistence; - to the wider environment: network contacts, logons, web requests.

It then asks Jev, TypeSafe's structured-decision model, about each process, account, host, address or domain those links reach. What Jev links is followed further, round by round, until nothing new joins. The result is the incident, a timeline of what it did, and how each part joined.

Badge

For the project's own README, linking back here:

Listed in Jev in production

Also used for search, ranking and matching