FIND EVIL! · Evidence-Locked DFIR Agent · 8-component review hub
FIND EVIL!

Evidence-Locked DFIR Agent

AI can help find evil, but evidence decides what is true. The agent runs a suspicious-email investigation where every supported claim cites evidence, unsupported malware execution is blocked, original artifacts stay read-only, and containment remains a human decision.

30-Second Judge Path

1Run proof

Open the terminal run or run bash findevil/scripts/run_findevil_local_checks.sh.

2Check self-correction

The malware-execution claim is downgraded because process evidence does not prove execution.

3Audit evidence

Dataset hashes, evidence IDs, accuracy report, and execution log are linked from this page.

4Read the boundary

SIFT-ready artifact shape and MCP-ready tool contract are shown without claiming live SIFT execution.

8/8required FIND EVIL submission components mapped
5claims scored against packaged ground truth
0false confident supported claims
1unsupported execution claim blocked

Official Requirement Coverage

ComponentWhere to verifyStatus
Repository + licenseGitHub / MIT licensecovered
Demo videoYouTube and local MP4 with audiocovered
Architecture diagramdiagram and architecture notescovered
Dataset documentationdataset report and source hash manifestcovered
Accuracy + evidence integrityaccuracy report and integrity reportcovered
Execution logsJSONL log with timestamps and token fieldscovered

How AI Is Used

  • The AI agent proposes DFIR claims from case artifacts.
  • The evidence lock checks whether each claim cites concrete evidence IDs.
  • The self-correction path prevents unsupported execution certainty from reaching the report.
  • The analyst keeps containment authority.

What It Does Not Claim

  • No live SANS SIFT execution is claimed.
  • No real victim data or malware attribution is claimed.
  • No endpoint isolation is automated.
  • No destructive tool is exposed in the MCP-ready contract.
Evidence-Locked DFIR architecture diagram Terminal proof screenshot Evidence-locked DFIR report screenshot Shared AgentOps dashboard screenshot

Verify Locally

bash findevil/scripts/run_findevil_local_checks.sh

Expected markers: findevil_local_checks_ok, exact_status_accuracy=1.0, unsupported_claims_blocked=1, claim_boundary=verified_local_sift_ready_no_live_sift_execution_claim.