pwnsy
Runs on your device

Breach Timeline Builder

Paste dated breach and exposure notes, one per line, and get a sorted timeline with severity, the observables that link events, the gaps in your evidence and a report you can export.

Samples

Timeline

Paste dated evidence or load a sample.

How the breach timeline works

Each line is one event. One date is read from the line (ISO formats are tried before written and slash dates), the rest becomes the event text, and lines with no date are listed under the timeline so nothing is dropped.

  • Types come from keywords: leak (leak, dump, paste, forum, for sale), credentials (password, hash, SSO, MFA, session cookie), secrets (API key, token, commit, private key), exposure (exposed, bucket, misconfigured) and infrastructure (certificate, subdomain, VPN, CVE). A line with none of them is a note.
  • Severity adds points per type and for words such as ransomware, admin, password reuse, customer or finance. 6 or more is high, 3 to 5 is medium.
  • Observables: domains, emails, IPs, CVEs, hashes, AWS keys, GitHub and Slack tokens are pulled from each line.
  • Gaps: missing evidence types, rows without an observable, ambiguous dates and any gap longer than 45 days between events.

How to read the result

The axis spaces events by real time, coloured red for high, amber for medium and green for low severity; tap a dot to open that event. Each event shows its age, its types and its observables, and opens to next steps for its types. Pivots are the threads to pull first: the same host, email or key turning up on two dates. Severity is an evidence priority cue and does not prove a breach.

Breach timeline FAQ

Which date formats does it read?

2026-08-13, 2026/08/13, 2026-08-13T10:22Z, 20260813, 13 Aug 2026, 13 August 2026, Aug 13, 2026, 13.08.2026, 13/08/2026 (or 08/13/2026 with the month/day setting), and month-only dates such as Aug 2026. One date is read from each line: ISO dates are tried first, then compact, written, dotted and slash dates, then month-only dates, and the first format that matches is used.

What happens to slash dates like 03/09/2026?

When both parts are 12 or less, the Slash dates setting decides between day/month and month/day, and the event is flagged as an ambiguous date. When one part is above 12, the order is worked out from it.

How is severity scored?

Keywords add points: 3 for a leak, 3 for credentials, 2 for secrets, 2 for exposure, 3 more for words such as ransomware, admin, password reuse, customer, finance, AWS key, private key or session cookie, and 1 for a claim, sale or sample. 6 points or more is high, 3 to 5 is medium, less is low. You can change any severity by hand.

What is a pivot?

An observable that appears in two or more events: a domain, email, IP address, CVE, hash, AWS key, GitHub token or Slack token. Pivots link events that may belong to the same incident. Tap one to filter the timeline to those events.

Are my notes uploaded or saved?

No. Parsing runs in this page, nothing is sent to a server, and the notes are not saved in the browser. Export CSV or JSON if you want to keep the timeline.

Use public signals: leak claims, credential sightings, repo secrets, exposed hosts, certificate changes and disclosures.

Report copied