FORENSIC HORIZON ARCADE

How far back can you investigate?

Run the timeline. Collect the evidence. Find out what disappears before the investigation even begins.

NO SIGNUP · 3 MINUTES · BEST PLAYED WITH SOUND ON

EVIDENCE RUN

A single-run arcade cabinet about retention windows, correlation and the evidence that was gone before anyone asked for it.

HOW IT WORKS

01

Collect evidence

EDR, DNS, VPN, firewall, cloud audit, identity and application logs, picked up as you run the incident timeline.

02

Beat retention

Evidence expires as the breach gets older. Each source has its own window, and the run keeps moving.

03

Reconstruct the chain

Your score depends on how much of Initial Access, Authentication, Execution, Data Access and Exfiltration can still be corroborated.

EVIDENCE SOURCES AND GAME RETENTION

  • EDR90d
  • AUTH180d
  • VPN180d
  • DNS30d
  • PROXY90d
  • FIREWALL365d
  • CLOUD180d
  • APP30d
  • DB AUDIT60d
  • NETFLOW90d

Game mechanics, not retention advice.

POWER-UPS AND HAZARDS

  • THE OLD SYSADMIN +30 days of undocumented institutional memory.
  • FINANCE APPROVED STORAGE Retention doubled. Nobody knows how.
  • SIEM ARCHIVE Someone actually kept the cold tier.
  • LOG ROTATION Gone means gone.
  • DISK FULL Logging stopped three weeks ago.
  • AUDITING DISABLED For performance reasons.

Six power-ups and seven hazards are in the cabinet. You will recognise most of them.

WHY IT MATTERS

A 365-day firewall archive does not give you a 365-day forensic capability if the EDR, identity and application evidence needed to explain that traffic disappeared months ago.

Forensic Horizon measures the oldest incident your organization can still reconstruct with confidence across the evidence chain.

The game gives you a score. Your environment deserves a real answer.

Visit Forensic Horizon