DeepDig – Windows Event Log Analyzer
Windows already records everything that happens on a machine — DeepDig makes sense of it. It reads the event logs your PC already keeps and turns thousands of cryptic entries into clear, plain-English security and stability incidents, each with a readable story and concrete remediation steps. Everything runs on your PC: no cloud, no account, no telemetry.
Download Version 1.1.0
Available on the Microsoft Store — no subscription, no ads.
Or view the listing at apps.microsoft.com.
From raw logs to real answers
Instead of leaving you to scroll through Event Viewer, DeepDig correlates related alerts into incidents — each with a plain-English narrative, severity, recommended actions and a MITRE ATT&CK mapping. On a local scan it also runs a read-only Registry Security Audit, surfacing persistence, privilege-escalation and defense-evasion risks with evidence and fixes. It reads only Windows’ own logs and registry, processes everything locally, and never uploads your data.
Changelog — what's new in each release
Full release history through 1.1.0 — which cut a real machine’s 279 false “incidents” down to the 13 genuine ones, stopped a rescan inventing detections, and added scan time ranges, multi-file analysis, search and filtering.
View the full changelogUser Guide — every step explained
A plain-English walkthrough of scanning this PC or an offline .evtx file, reading incidents and trends, the registry security audit, live monitoring and exporting your findings.
Read the User GuideFeatures
🧩 Plain-English Incidents
Related alerts are correlated into incidents with a readable narrative, severity and recommended fixes — not just a wall of raw event IDs.
🛡️ Built-in Threat Detection
Detection rules covering credential access, persistence, privilege escalation, lateral movement (including RDP logons), defense evasion (Defender tampering, audit-log clearing), execution, stability and performance.
🗂️ Live Scan or Offline .evtx
Scan this PC live, or import an exported .evtx file from another machine — one detection engine handles both. Drag-and-drop a log straight onto the window.
📡 Real-Time Live Monitoring
Flip on Live to stream new alerts as they happen, with continuously updated correlation so incidents stay current.
📊 Trends & Charts
Built-in charts show activity over time, top event types and category breakdowns. Click any bar to drill straight into the underlying events.
🔁 Last-Reboot Card
See your last boot time and reason, and whether it was planned or unexpected — click through for the full startup and shutdown history.
🧬 Registry Security Audit
A read-only audit of startup keys, Winlogon, IFEO debuggers, UAC-bypass artifacts, Defender disabling/exclusions, PowerShell policy, suspicious services, remote-access tools, and USB/RDP history — each with evidence, remediation and a MITRE ATT&CK mapping.
🧹 Noise Control & Export
Recurring detections collapse into a single “seen N×” card, anything you trust can be marked expected to stay hidden, and findings export to CSV or JSON. An expected-items manager lets you review everything you have hidden and restore items one at a time rather than all at once.
🔎 Triage Controls
Search and filter by severity across the incident list, with a live “X of Y” count. Narrow a scan to the last 24 hours, 7 days or 30 days — live channels are filtered at the source, so a narrower window is genuinely faster rather than read-then-discarded. A Cancel button stops a scan already under way.
🗃️ Several Files, One Timeline
Open several .evtx files at once — multi-select or drop a batch — and DeepDig analyses them as a single correlated timeline. A corrupt or locked file in the batch is skipped without costing you the rest. For an imported file, a time range is anchored on that file’s own newest event, so “last 7 days” of a months-old export still means its last 7 days.
.evtx file, which needs no admin.
Latest Release
Version 1.1.0 — September 1, 2026
A correctness, accessibility and triage release. Crash detection no longer matches any source that happens to share an event ID — on one real machine that alone cut 279 “incidents” to 13 — and rescanning a log no longer invents detections that were never in it. New: scan time ranges, a Cancel button, opening several .evtx files as one timeline, an expected-items manager, and search and severity filtering over the incident list.