Jev in production › Search, ranking and matching
Jev scores how related processes, accounts and hosts are to one confirmed-malicious indicator, expanding it into a full incident timeline for analysts.
Start from one process, address, account or host you know is malicious. Get back the incident.
Once an analyst confirms one malicious process, the next question is always what else is part of this?
Jevline follows every link the telemetry records out of it: - between processes: children, code injection, files dropped and then run, persistence; - to the wider environment: network contacts, logons, web requests.
It then asks Jev, TypeSafe's structured-decision model, about each process, account, host, address or domain those links reach. What Jev links is followed further, round by round, until nothing new joins. The result is the incident, a timeline of what it did, and how each part joined.
For the project's own README, linking back here: