Devpost
Participate in our public hackathons
Devpost for Teams
Access your company's private hackathons
Grow your developer ecosystem and promote your platform
Drive innovation, collaboration, and retention within your organization
By use case
Blog
Insights into hackathon planning and participation
Customer stories
Inspiration from peers and other industry leaders
Planning guides
Best practices for planning online and in-person hackathons
Webinars & events
Upcoming events and on-demand recordings
Help desk
Common questions and support documentation
A fully autonomous forensic investigator with 140+ typed tools, quality-gated phases, adversarial self-review, and an architecture that makes hallucinated findings nearly impossible.
Built on the idea that we're all smarter than any of us: TRUDI pairs an autonomous DFIR agent with an AI reviewer that challenges its findings, so every conclusion is traceable and trustworthy.
A 'code-mode' MCP server that allows LLMs to safely generate and execute JavaScript code that calls forensic tools, high-level workflows, and employs classical ML algorithms, using SIFT workstation.
Autonomous ROS2 robot forensics agent that proves what it found! Not just Cyber friendly but Physically intact also! And hallucination free :)
Autonomous DFIR pipeline for SIFT that investigates memory, disk,and event evidence in 1 controlled run, surfaces uncertainty and not hide, and produces findings responders can trust under pressure.
An autonomous AI agent system that detects, analyzes, and responds to cybersecurity threats in real-time — combining static analysis scanners with LLM-powered triage and adversarial self-correction.
The reasoning kernel between LLM agents and forensic toolchains — turns "investigate this disk image" into methodology-driven, evidence-grade incident reports.
A custom MCP server that turns Claude Code into an IR analyst on the SANS SIFT VM — live triage, memory forensics, Plaso timelines, and an audit-trailed case file, all chained autonomously.
The Autonomous Multi-Agent Forensic Harness Built By Agents for Agents to operate at machine speed.
Deterministic ghost-artifact engine with architectural self-correction — measured F1, 8 MCP tools, live SIFT pipeline.
Fabrication isn't caught by a grader. It's a state the architecture can't represent.
AI-powered IR agent with 13 specialized detectors+ Llama 3.1, detect, LLM analyze, MITRE ATT&CK tactics, and automated isolation for multi-vector attacks. Severity scoring. Machine speed response.
AI attackers move at machine speed, while incident response remains manual. Our agent triages disk+memory at machine speed every finding cited, zero hallucinations, evidence read-only by design.
A benchmark for autonomous DFIR agents that scores not just what they find, but whether they retract false positives, verify negatives, and cite evidence for every claim.
AI agents shouldn't be one bad prompt away from spoiling evidence. We put a policy engine and enforcement between the agent and tool calls - Agents can't spoil evidence because the kernel won't let it
A multi-agent DFIR that processes evidence, runs playbooks, generates reports and lets you interrogate cases through a conversational RAG. Geoff can run fully locally with no internet required.
Multi-agent DFIR triage that reads memory and disk images, pivots like a real analyst, and writes an complete incident report in minutes for pocket change. Forensics that never sleeps.
An autonomous, read-only DFIR triage agent that finds evil at machine speed — every finding grounded in tool output, red-teamed, and hash-chained, so it never hallucinates or touches the evidence.
Forensic AI governance layer — every tool call sealed, every finding traceable, prompt injection blocked before the LLM ever sees it.
Autonomous NTFS anti-forensics triage for Protocol SIFT: it finds timestomping, self-corrects, and is built so a hallucinated finding is structurally impossible.
EvilTrace — A Self-Correcting, Evidence-Grounded DFIR Agent for Protocol
LinuxIR Agent is a multi-agent Linux incident response platform that closes the gap between AI threat speed and defensive response time.
MemoryHound turns Claude Code into an autonomous DFIR analyst. Drop evidence into a folder, run one command, get a signed forensic report.
A dual-agent DFIR architecture that eliminates hallucination through structural citation enforcement and prevents evidence spoliation architecturally with no prompt guardrails relied upon.
1 – 24 of 118