Evidence-Locked DFIR Agent
AI can help find evil, but evidence decides what is true. The agent runs a suspicious-email investigation where every supported claim cites evidence, unsupported malware execution is blocked, original artifacts stay read-only, and containment remains a human decision.
30-Second Judge Path
Open the terminal run or run bash findevil/scripts/run_findevil_local_checks.sh.
The malware-execution claim is downgraded because process evidence does not prove execution.
Dataset hashes, evidence IDs, accuracy report, and execution log are linked from this page.
SIFT-ready artifact shape and MCP-ready tool contract are shown without claiming live SIFT execution.
Official Requirement Coverage
| Component | Where to verify | Status |
|---|---|---|
| Repository + license | GitHub / MIT license | covered |
| Demo video | YouTube and local MP4 with audio | covered |
| Architecture diagram | diagram and architecture notes | covered |
| Dataset documentation | dataset report and source hash manifest | covered |
| Accuracy + evidence integrity | accuracy report and integrity report | covered |
| Execution logs | JSONL log with timestamps and token fields | covered |
How AI Is Used
- The AI agent proposes DFIR claims from case artifacts.
- The evidence lock checks whether each claim cites concrete evidence IDs.
- The self-correction path prevents unsupported execution certainty from reaching the report.
- The analyst keeps containment authority.
What It Does Not Claim
- No live SANS SIFT execution is claimed.
- No real victim data or malware attribution is claimed.
- No endpoint isolation is automated.
- No destructive tool is exposed in the MCP-ready contract.
Verify Locally
bash findevil/scripts/run_findevil_local_checks.sh
Expected markers: findevil_local_checks_ok, exact_status_accuracy=1.0, unsupported_claims_blocked=1, claim_boundary=verified_local_sift_ready_no_live_sift_execution_claim.