Most blue team tooling assumes you have a SIEM, a budget, and a network connection. That's a fine assumption for an enterprise SOC, but it kills the feedback loop for students, home-labbers, IR consultants who land in air-gapped environments, and anyone who just wants to triage a dump of logs without spinning up infrastructure.

That's the gap I...