KeyStone Forensics

KeyStone Forensics

KeyStone Forensics is Shapstone’s post-event investigation and reporting module within the KeyStone Grid Intelligence platform. After a disturbance, security incident, or unplanned outage, Forensics reconstructs the sequence of system states and produces traceable analysis packages for root-cause studies and compliance reporting.

Key capabilities

  • Event sequence reconstruction. Reconstructs the chronological sequence of system states from protective relay event reports, SCADA logs, and breaker position records.
  • Multi-source data correlation. Correlates telemetry from distributed feeders, substations, and DER interconnection points into a unified timeline.
  • Automated compliance reporting. Generates NERC, IEEE, and internal post-mortem reports with embedded evidence chains.
  • Root-cause analysis. Identifies primary and contributing causes of incidents with confidence metrics and uncertainty bounds.
  • Exportable analysis packages. Produces stakeholder-ready packages including visualizations, raw data extracts, and audit trails.

How it works

Forensics ingests historical data from the moments surrounding an event — typically 24 hours before through 24 hours after. Its models reconstruct system state at sub-second intervals, correlate protective device operations, and identify deviations from expected behavior. The module then produces a structured analysis package that includes a visual timeline, correlation heat maps, and an evidence chain suitable for regulatory review.

Value for utilities

Utilities using KeyStone Forensics benefit from:

  • Weeks saved on manual post-event analysis.
  • Compliance-ready reports submitted without additional engineering effort.
  • Faster learning cycles from past events, reducing recurrence risk.
  • Audit-ready traceability for every analysis, decision, and data point.

Forensics works alongside Locate for fault detection context, Assure for validation, and Twin for scenario simulation of similar future conditions.