TraceHawk — Security Log Analyzer
Problem: Security investigations need explainable detection and durable evidence without requiring a full enterprise SIEM.
My role: I designed and built the local-first investigation workflow, API, interface, rules, reports, and release verification.
Outcome: The public v0.10.0 system combines deterministic detection, multi-source cases, line-level evidence, bounded monitoring, and redactable reports. It is a single-replica portfolio system, not a production SOC platform.