Devpost
Participate in our public hackathons
Devpost for Teams
Access your company's private hackathons
Grow your developer ecosystem and promote your platform
Drive innovation, collaboration, and retention within your organization
By use case
Blog
Insights into hackathon planning and participation
Customer stories
Inspiration from peers and other industry leaders
Planning guides
Best practices for planning online and in-person hackathons
Webinars & events
Upcoming events and on-demand recordings
Help desk
Common questions and support documentation
Elenchos is bounded autonomous DFIR triage for SIFT: model-led orchestration, deterministic evidence, policy gates, and audit trails that refuse unsupported claims.
Forensics for AI agents with guardrails built into the server, not written in the prompt
Autonomous incident response that can't hallucinate — every finding is grounded in the tool output that proves it, or it doesn't ship.
Auditable autonomous forensics for SANS SIFT — every AI finding grounded, verified, and traceable.
AI is fast at searching a hacked computer, but it makes things up. COUNSEL only confirms what the evidence actually backs, and signs every step so you can check its work.
A junior reads the timestamp and closes the case. Stomped reads the journal underneath it, and reopens the one the attacker backdated. Confirmed, inferred, or contradicted — never just asserted.
Catches AI hallucinations with code, not more AI. Five deterministic validators - zero LLM - verify every finding against actual tool output before it reaches the report.
An autonomous incident-response agent for SANS SIFT that physically can't tamper with evidence or hallucinate findings — every result traces to a logged tool call you can verify in under 10 seconds.
Autonomous DFIR at adversary speed. Architectural guardrails block evidence tampering in code. Self-corrects via cross-artifact verification. F1=1.00
i have let claude code create a dashboard for analysts, i think it meets all the requirements
A hypothesis-first DFIR investigator
A custom MCP server that hands Claude 73 typed, read-only forensic functions — autonomous DFIR triage where every finding is traceable to a tool call and hallucination is structurally impossible.
Autonomous DFIR agent on SANS SIFT that processes evidence through a read-only MCP boundary, per-call audit log, and a self-correcting validator loop.
A local, defensive autonomous SOC for DFIR. A swarm fuses evidence and decides in under a millisecond — no LLM on the decision path — and signs every call into a tamper-evident ledger.
A 4-agent AI pipeline that catches its own hallucinations before writing the DFIR report
Tribunal puts AI's forensic findings on trial: one agent accuses, one cross-examines, one rules—so only evidence that survives cross-examination is sealed into a court-ready chain of custody.
An MCP server with architectural guardrails wrapping SIFT tools as typed safe functions, plus a self-correcting LangGraph agent that investigates like a senior analyst.
Autonomous Windows-forensics IR agent: signatures with zero runtime LLM, then an LLM that actively hunts artifacts and reads real file contents off the disk image, self-correcting as it goes.
An experimental proof-of-concept orchestrator that automates the initial "first pass" of digital evidence triage using strict read-only constraints. Built for the SANS FIND EVIL Hackathon 2026.
DigiSec is an autonomous AI DFIR platform with strict zero-spoliation guardrails. It safely isolates evidence, correlates disk/memory artifacts, and generates courtroom- ready PDF reports.
Self-correcting DFIR triage on SIFT where trust is architectural, not prompted: no write tool exists, every finding is hash-bound, and a rival model verifies it.
A read-only Neo4j graph-correlation layer that extends Protocol SIFT, giving an autonomous DFIR agent cross-host, cross-time memory of a case, with read-only enforced by architecture.
Autonomous AI Security Triage Agent — Splunk + SANS SIFT MCP · Gemini 2.5 Flash.
AI agents debate forensic evidence like senior analysts, catching what single-agent tools miss and clearing what they falsely flag.
25 – 48 of 118