Open the separate evidence-analysis workspace.
All tools, attack artifacts, malware behavior, and logs are simulated.