The normalization engine that turns raw evidence into structured investigations.
PowerLens is the second pillar of the PowerForensics ecosystem. It acts as the critical bridge between evidence collection (PowerTriage) and advanced analysis (Chronos and Nexus).
Without normalization, data is just noise. PowerLens processes heterogeneous logs and transforms them into a unified format (JSON) ready for visualization and correlation.
Originally conceived as a support component, PowerLens has evolved to become the central processing engine, ensuring that every piece of evidence has its place in the timeline and relationship graph.
Converts disparate formats (Syslog, EVTX, JSON, CSV and cloud logs) into a common structure understandable by the ecosystem.
The current scope includes AWS CloudTrail, Microsoft Purview / Office 365 UAL, and Entra ID Sign-Ins, generating outputs ready for Chronos and Nexus.
The Azure Monitor path has partial support, while Google Cloud Audit Logs remains planned before publication.
Generates reusable structures for Chronos and Nexus, reducing the need for manual data conversion.