Skip to content

Releases: aptwatcher/APTWatcher

APTWatcher DFIR — FIND EVIL! hackathon submission

Choose a tag to compare

@aptwatcher aptwatcher released this 13 Jun 20:37

First public cut of APTWatcher DFIR for the FIND EVIL! hackathon (SANS/GIAC).

Autonomous defensive DFIR agent on Protocol SIFT: read-only evidence handling,
consent-gated tools above tier 0, and an append-only signed audit log.

  • 51 MCP tools (42 tier-0 read-only forensic + 9 tier-1 intel)
  • 9 CLI subcommands; 10/10 SIFT tool wrappers
  • 32 clean-room knowledge-base entries
  • Dry-run publication adapters (Netcraft, MISP, GLPI, TAXII 2.1, stub)

Alpha — interfaces may change. Install: see README quick start.