Devpost
Participate in our public hackathons
Devpost for Teams
Access your company's private hackathons
Grow your developer ecosystem and promote your platform
Drive innovation, collaboration, and retention within your organization
By use case
Blog
Insights into hackathon planning and participation
Customer stories
Inspiration from peers and other industry leaders
Planning guides
Best practices for planning online and in-person hackathons
Webinars & events
Upcoming events and on-demand recordings
Help desk
Common questions and support documentation
An autonomous incident response analyst for the SANS SIFT Workstation that cannot modify evidence and cannot confidently report something it has not proven.
Network, memory and storage forensics in one tool that connects the dots for you. Ask a question, get an evidence-backed answer, and a finished incident report in days instead of months.
SIFT-MIND teaches AI what it cannot know. A deterministic, cryptographically-bound epistemic ledger that blocks hallucinated forensic reports on SANS SIFT.
Autonomous IR agent on Protocol SIFT — custom MCP, Claude Code, LangGraph — verifies forensic evidence read-only and finds keyloggers, stolen credentials, and malware on the M57 USB case.
Protocol SIFT can't spoliate evidence it physically can't touch. APEX Forensics enforces read-only tools, hash-chains every action, and flags confirmed vs. inferred findings.
Self-correcting AI agent for digital forensics. Validates its own findings, detects contradictions, and re-investigates automatically using real forensic analysis.
An autonomous DFIR agent that investigates a Windows intrusion end-to-end, then adversarially verifies every finding. Every finding cited, every action audited, zero hallucinated evil.
73 MCP tools (16 SIFT forensic wrappers) behind one MCP interface — an agent swarm runs days of disk + memory forensic triage in minutes, with every finding deterministic and hashed.
Turns Claude Code into a guardrailed DFIR investigation agent: one manifest over collected disk and memory evidence; correlates, self-corrects on contradictions, ships auditable reports.
AIFT is a GUI, CLI, REST API, and MCP tool that helps DFIR analysts get oriented quickly. Point it at evidence and parses artifacts with Dissect, and uses AI to turn parsed data into a traige report.
A forensically-defensible autonomous DFIR analyst: read-only by construction, adversarially self-correcting, with a tamper-evident chain of custody.
An autonomous, self-correcting DFIR agent on SANS SIFT, leveraging LangGraph & FastMCP to triage, correlate, and produce executive reports in under 8 minutes, matching state-level threat speeds.
A forensic investigation agent that cannot hallucinate findings — every claim is SQL-assertion-gated, chain-of-custody hashed, and replayable. Precision enforced by architecture, not by prompt.
AI‑powered agent that ingests SIEM logs, auto‑triages threats using SANS SIFT & MITRE ATT&CK frameworks, and generates professional incident reports featuring local LLM fallback for offline resilience
An AI agent that autonomously finds evil on a forensic disk image — driving a SIFT Workstation through
An autonomous DFIR agent that finds evil in under 10 minutes with a full attack timeline - calling 190+ typed tools through an MCP server, with parallel 4-AI calling and 8 workers make most efficient.
Verifier-first boundary for SIFT triage: confirmed findings must prove themselves with evidence refs, tool-call logs, verifier correction, and integrity hashes.
Autonomous DFIR agent for Claude Code that verifies every finding; 0.0% hallucination.
A DFIR agent: point it at digital evidence and it returns a signed verdict — is there evil here? — with every finding citing the exact tool call, in a chain of custody you can verify offline.
Protocol SIFT implementation with full audit log traceability, reduced hallucinations, and improved consistency.
Claude Code/OpenClaw-ready DFIR triage with an MCP evidence layer that refuses hallucinated findings and treats hostile log text as data.
"Making forensic evasion expensive — every manipulation attempt leaves a semiotic trace."
A forensically defensible AI agent for Windows DFIR: typed read-only primitives, hash-chained audit log, separation-of-duties three-agent architecture. Verified by construction, not by prompt.
Multi-agent AI that autonomously investigates endpoint compromises using SIFT forensic tools - from memory to disk to MITRE, with full audit trail and human-in-the-loop approval.
73 – 96 of 118