Create event records
Enter each observed action or finding as a separate event and pair its description with a timestamp. Add a category to distinguish activities such as authentication, endpoint detection, network traffic, containment, or communications. An evidence reference can identify the supporting log entry, alert, message, ticket, screenshot, or case artifact. The builder presents these structured records as a timeline without determining whether the evidence is accurate.