Skip to content

Latest commit

 

History

History
109 lines (80 loc) · 4.43 KB

File metadata and controls

109 lines (80 loc) · 4.43 KB

APTWatcher DFIR Documentation

Autonomous digital-forensics & incident-response agent for the SANS SIFT Workstation. Built on Protocol SIFT for the FIND EVIL! hackathon (SANS/GIAC, 2026).

This is the canonical documentation. Every page is plain Markdown — renders natively on GitHub, and builds into a searchable static site via mkdocs + Material theme.


Start here

If you are… Read
A first-time user Getting started
A hackathon judge Getting started → Try it out and Architecture
A senior IR analyst Scenarios and Use cases
A developer extending APTWatcher Architecture, Reference, and design/

Navigation

How to install and run APTWatcher in each deployment mode.

How APTWatcher is structured and why.

Pre-flight profiles that bound what tools the agent can reach for.

End-to-end demo scenarios — each one comes with a dataset, an expected agent approach, and a success rubric.

How we generate synthetic test cases and which public datasets we use.

Optional external capabilities wired into the tier model.

Flat lookup tables.

Low-level implementation references — mostly for developers.

Hackathon submission


Contributing

Corrections, additional scenarios, and new knowledge-base entries are welcome — see the clean-room content policy for what can and cannot go into the KB.

License

MIT. Third-party attributions are listed per integration page.