• Devpost Devpost
    • Log in
    • Sign up
    Join a hackathon
    Devpost logo

    Devpost

    Participate in our public hackathons

    Hackathons Projects
    Devpost for Teams

    Devpost for Teams

    Access your company's private hackathons

    Login
    Host a hackathon
    Devpost

    Devpost

    Grow your developer ecosystem and promote your platform

    Host a public hackathon
    Devpost for Teams logo

    Devpost for Teams

    Drive innovation, collaboration, and retention within your organization

    Host an internal hackathon

    By use case

    AI hackathons Customer hackathons Employee hackathons Public hackathons
    Resources

    Blog

    Insights into hackathon planning and participation

    Customer stories

    Inspiration from peers and other industry leaders

    Planning guides

    Best practices for planning online and in-person hackathons

    Webinars & events

    Upcoming events and on-demand recordings

    Help desk

    Common questions and support documentation

  • Devpost Devpost
  • Join a hackathon
    • Devpost logo

      Devpost

      Participate in our public hackathons

      Hackathons Projects
      Devpost for Teams

      Devpost for Teams

      Access your company's private hackathons

      Login
  • Host a hackathon
    • Devpost

      Devpost

      Grow your developer ecosystem and promote your platform

      Host a public hackathon
      Devpost for Teams logo

      Devpost for Teams

      Drive innovation, collaboration, and retention within your organization

      Host an internal hackathon

      By use case

      AI hackathons Customer hackathons Employee hackathons Public hackathons
  • Resources
    • Blog

      Insights into hackathon planning and participation

      Customer stories

      Inspiration from peers and other industry leaders

      Planning guides

      Best practices for planning online and in-person hackathons

      Webinars & events

      Upcoming events and on-demand recordings

      Help desk

      Common questions and support documentation

  • Log in
  • Sign up

FIND EVIL!

Descend
  • Overview
  • My projects
  • Participants (4404)
  • Resources
  • Rules
  • Project gallery
  • Updates
  • Discussions
Connect with the participants – support your favorite projects by liking, sharing, and commenting on them.
Elenchos
Elenchos

Elenchos is bounded autonomous DFIR triage for SIFT: model-led orchestration, deterministic evidence, policy gates, and audit trails that refuse unsupported claims.

OCHOLA ODHIAMBO
0 0
Sanctum
Sanctum

Forensics for AI agents with guardrails built into the server, not written in the prompt

Jason Tofte
0 0
Grounded Autonomous DFIR Agent
Grounded Autonomous DFIR Agent

Autonomous incident response that can't hallucinate — every finding is grounded in the tool output that proves it, or it doesn't ship.

Rome Thorstenson
0 0
DeepSIFT
DeepSIFT

Auditable autonomous forensics for SANS SIFT — every AI finding grounded, verified, and traceable.

Ahammad Shawki + 1
0 0
COUNSEL - AI forensics that won't make things up
COUNSEL - AI forensics that won't make things up

AI is fast at searching a hacked computer, but it makes things up. COUNSEL only confirms what the evidence actually backs, and signs every step so you can check its work.

Ujwal Suresh Vanjare Arpita Madhukar Kalburgi
0 0
Stomped
Stomped

A junior reads the timestamp and closes the case. Stomped reads the journal underneath it, and reopens the one the attacker backdated. Confirmed, inferred, or contradicted — never just asserted.

Kenneth Chen
0 0
SIFT Sentinel
SIFT Sentinel

Catches AI hallucinations with code, not more AI. Five deterministic validators - zero LLM - verify every finding against actual tool output before it reaches the report.

Aditya Chauhan Vova Hegai
1 0
Find Evil! — Verifiable Autonomous IR Agent
Find Evil! — Verifiable Autonomous IR Agent

An autonomous incident-response agent for SANS SIFT that physically can't tamper with evidence or hallucinate findings — every result traces to a logged tool call you can verify in under 10 seconds.

Manoj Mallick
0 0
4n6 Nexus
4n6 Nexus

Autonomous DFIR at adversary speed. Architectural guardrails block evidence tampering in code. Self-corrects via cross-artifact verification. F1=1.00

Jonathan Tomek
1 0
brclco
brclco

i have let claude code create a dashboard for analysts, i think it meets all the requirements

Br clco
0 0
Slient WItness
Slient WItness

A hypothesis-first DFIR investigator

Blockchain Oracle
0 0
Agentic-DART
Agentic-DART

A custom MCP server that hands Claude 73 typed, read-only forensic functions — autonomous DFIR triage where every finding is traceable to a tool call and hallucination is structurally impossible.

Juwon Bang Sejoon Oh Geonhui Lee Yongsoo Kwon
5 0
SIFT-OWL
SIFT-OWL

Autonomous DFIR agent on SANS SIFT that processes evidence through a read-only MCP boundary, per-call audit log, and a self-correcting validator loop.

Timo Miettinen
0 0
Stigmergy
Stigmergy

A local, defensive autonomous SOC for DFIR. A swarm fuses evidence and decides in under a millisecond — no LLM on the decision path — and signs every call into a tamper-evident ledger.

Shaugato paroi
0 0
SIFT-Veritas
SIFT-Veritas

A 4-agent AI pipeline that catches its own hallucinations before writing the DFIR report

Ammar Ahmed
1 0
The Tribunal
The Tribunal

Tribunal puts AI's forensic findings on trial: one agent accuses, one cross-examines, one rules—so only evidence that survives cross-examination is sealed into a court-ready chain of custody.

Divyansh Divyansh Sanskar Shree
0 0
SIFT MCP Forensic Agent
SIFT MCP Forensic Agent

An MCP server with architectural guardrails wrapping SIFT tools as typed safe functions, plus a self-correcting LangGraph agent that investigates like a senior analyst.

Anjali Jha
0 0
TLVB
TLVB

Autonomous Windows-forensics IR agent: signatures with zero runtime LLM, then an LLM that actively hunts artifacts and reads real file contents off the disk image, self-correcting as it goes.

liuchuandahui417 Yanagawa sagi kasa iria piyo dn wt
0 0
 Autonomous DFIR Triage Pipeline
Autonomous DFIR Triage Pipeline

An experimental proof-of-concept orchestrator that automates the initial "first pass" of digital evidence triage using strict read-only constraints. Built for the SANS FIND EVIL Hackathon 2026.

Bayarod Ankhbayar
0 0
DigiSec
DigiSec

DigiSec is an autonomous AI DFIR platform with strict zero-spoliation guardrails. It safely isolates evidence, correlates disk/memory artifacts, and generates courtroom- ready PDF reports.

mohammad amin
1 0
Glass Box — Self-Correcting DFIR Triage Agent
Glass Box — Self-Correcting DFIR Triage Agent

Self-correcting DFIR triage on SIFT where trust is architectural, not prompted: no write tool exists, every finding is hash-bound, and a rival model verifies it.

Dheeraj Shrivastav Nikhil Tale + 1
0 0
neo-finds-evil (Warwick Cyber)
neo-finds-evil (Warwick Cyber)

A read-only Neo4j graph-correlation layer that extends Protocol SIFT, giving an autonomous DFIR agent cross-host, cross-time memory of a case, with read-only enforced by architecture.

hackforfun Malinowski Bharath Sadasivaiah Nikhil Kuwar Maria Papadaki + 1
0 0
Sentinel Zero
Sentinel Zero

Autonomous AI Security Triage Agent — Splunk + SANS SIFT MCP · Gemini 2.5 Flash.

Kushal Soni
0 0
 PHANTOM DFIR
PHANTOM DFIR

AI agents debate forensic evidence like senior analysts, catching what single-agent tools miss and clearing what they falsely flag.

Romil Patel
0 0

25 – 48 of 118

  • «
  • 1
  • 2
  • 3
  • 4
  • 5
  • »

Devpost

  • About
  • Careers
  • Contact
  • Help

Hackathons

  • Browse hackathons
  • Explore projects
  • Host a hackathon
  • Hackathon guides

Portfolio

  • Your projects
  • Your hackathons
  • Settings

Connect

  • Twitter
  • Discord
  • Facebook
  • LinkedIn
© 2026 Devpost, Inc. All rights reserved.
  • Community guidelines
  • Security
  • CA notice
  • Privacy policy
  • Terms of service