FIND EVIL! · Evidence-Locked DFIR Agent · Demo Artifact

AI can move fast in DFIR, but every claim must stay tied to evidence.

This report shows an AI-assisted suspicious email investigation where the agent flags its own unsupported malware-execution claim, redacts low-confidence indicator output, and leaves the final containment decision to a human analyst.

8evidence events in this DFIR case
1AI self-correction guardrail event
1redacted low-confidence indicator
1human containment approval

Hypotheses And Status

Supported

Suspicious email / phishing attempt

Supported at low-to-medium confidence by collected artifacts and hash lookup.

evt-0014 evt-0017

Not supported

Endpoint malware execution

The agent flagged this as unsupported because process evidence was missing.

evt-0015 evt-0016

Human decision

Mailbox-only containment

Human analyst approved message containment and did not approve endpoint isolation.

evt-0018

Evidence Chain

Event Phase Actor Evidence Summary
evt-0012 intake security-analyst Security analyst opened a suspicious email investigation with attached endpoint telemetry.
evt-0013 planning dfir-analysis-agent Agent proposed an evidence-first DFIR plan: preserve artifacts, list hypotheses, then verify each claim.
evt-0014 evidence_collection sift-collector Collected email headers, attachment hash, browser download timeline, and endpoint process list.
evt-0015 investigation dfir-analysis-agent Agent generated an initial hypothesis but flagged one claim as unsupported by current evidence.
evt-0016 risk_review dfir-analysis-agent System marked the draft finding as provisional because execution evidence was missing.
evt-0017 evidence_collection threat-intel-api Hash lookup returned low-confidence phishing kit association; raw indicator was redacted in report output.
evt-0018 approval security-analyst Human approved containment of the reported message and requested no endpoint isolation.
evt-0019 handoff agentops-recorder Generated DFIR report with evidence IDs, unsupported claims, and human containment decision.

Guardrails

Event Risk Reason Decision
evt-0015 medium Initial model answer overclaimed malware execution before process evidence was present. none
evt-0016 high Unsupported certainty detected in analyst draft. none
evt-0017 medium human approval / redaction guardrail none
evt-0018 low human approval / redaction guardrail approved

Timeline

evt-0012 2026-05-19T12:08:12Z
task_start human / security-analyst

Security analyst opened a suspicious email investigation with attached endpoint telemetry.

none
evt-0013 2026-05-19T12:08:53Z
plan_update ai_agent / dfir-analysis-agent

Agent proposed an evidence-first DFIR plan: preserve artifacts, list hypotheses, then verify each claim.

low
evt-0014 2026-05-19T12:09:34Z
evidence_captured robot / sift-collector

Collected email headers, attachment hash, browser download timeline, and endpoint process list.

low
evt-0015 2026-05-19T12:10:15Z
ai_call ai_agent / dfir-analysis-agent

Agent generated an initial hypothesis but flagged one claim as unsupported by current evidence.

medium
evt-0016 2026-05-19T12:10:56Z
risk_signal ai_agent / dfir-analysis-agent

System marked the draft finding as provisional because execution evidence was missing.

high
evt-0017 2026-05-19T12:11:37Z
api_call api / threat-intel-api

Hash lookup returned low-confidence phishing kit association; raw indicator was redacted in report output.

medium
evt-0018 2026-05-19T12:12:18Z
approval_gate human / security-analyst

Human approved containment of the reported message and requested no endpoint isolation.

low
evt-0019 2026-05-19T12:12:59Z
handoff_report system / agentops-recorder

Generated DFIR report with evidence IDs, unsupported claims, and human containment decision.

none