• Devpost Devpost
    • Log in
    • Sign up
    Join a hackathon
    Devpost logo

    Devpost

    Participate in our public hackathons

    Hackathons Projects
    Devpost for Teams

    Devpost for Teams

    Access your company's private hackathons

    Login
    Host a hackathon
    Devpost

    Devpost

    Grow your developer ecosystem and promote your platform

    Host a public hackathon
    Devpost for Teams logo

    Devpost for Teams

    Drive innovation, collaboration, and retention within your organization

    Host an internal hackathon

    By use case

    AI hackathons Customer hackathons Employee hackathons Public hackathons
    Resources

    Blog

    Insights into hackathon planning and participation

    Customer stories

    Inspiration from peers and other industry leaders

    Planning guides

    Best practices for planning online and in-person hackathons

    Webinars & events

    Upcoming events and on-demand recordings

    Help desk

    Common questions and support documentation

  • Devpost Devpost
  • Join a hackathon
    • Devpost logo

      Devpost

      Participate in our public hackathons

      Hackathons Projects
      Devpost for Teams

      Devpost for Teams

      Access your company's private hackathons

      Login
  • Host a hackathon
    • Devpost

      Devpost

      Grow your developer ecosystem and promote your platform

      Host a public hackathon
      Devpost for Teams logo

      Devpost for Teams

      Drive innovation, collaboration, and retention within your organization

      Host an internal hackathon

      By use case

      AI hackathons Customer hackathons Employee hackathons Public hackathons
  • Resources
    • Blog

      Insights into hackathon planning and participation

      Customer stories

      Inspiration from peers and other industry leaders

      Planning guides

      Best practices for planning online and in-person hackathons

      Webinars & events

      Upcoming events and on-demand recordings

      Help desk

      Common questions and support documentation

  • Log in
  • Sign up

FIND EVIL!

Descend
  • Overview
  • My projects
  • Participants (4404)
  • Resources
  • Rules
  • Project gallery
  • Updates
  • Discussions
Connect with the participants – support your favorite projects by liking, sharing, and commenting on them.
VERDICT
VERDICT

An autonomous incident response analyst for the SANS SIFT Workstation that cannot modify evidence and cannot confidently report something it has not proven.

Tejas Mane
0 0
Fan Get Fame Fast
Fan Get Fame Fast

Network, memory and storage forensics in one tool that connects the dots for you. Ask a question, get an evidence-backed answer, and a finished incident report in days instead of months.

Richard de Vries Joost Beekman Jeffrey Everling
2 0
SIFT-MIND: Metacognitive Incident Response Orchestrator
SIFT-MIND: Metacognitive Incident Response Orchestrator

SIFT-MIND teaches AI what it cannot know. A deterministic, cryptographically-bound epistemic ledger that blocks hallucinated forensic reports on SANS SIFT.

Daksh-Aneja-Projects Aneja
0 0
SIFT-Analyst
SIFT-Analyst

Autonomous IR agent on Protocol SIFT — custom MCP, Claude Code, LangGraph — verifies forensic evidence read-only and finds keyloggers, stolen credentials, and malware on the M57 USB case.

07.IP.prakash raj.K Prakash raj
0 0
APEX Forensics
APEX Forensics

Protocol SIFT can't spoliate evidence it physically can't touch. APEX Forensics enforces read-only tools, hash-chains every action, and flags confirmed vs. inferred findings.

Jason Wold
1 0
SIFT Guardian
SIFT Guardian

Self-correcting AI agent for digital forensics. Validates its own findings, detects contradictions, and re-investigates automatically using real forensic analysis.

Aniket Mehra
0 0
VERDICT - Autonomous DFIR Agent That Proves Its Findings
VERDICT - Autonomous DFIR Agent That Proves Its Findings

An autonomous DFIR agent that investigates a Windows intrusion end-to-end, then adversarially verifies every finding. Every finding cited, every action audited, zero hallucinated evil.

0 0
Agentropix MCP: Agentic Forensics & Incident Response
Agentropix MCP: Agentic Forensics & Incident Response

73 MCP tools (16 SIFT forensic wrappers) behind one MCP interface — an agent swarm runs days of disk + memory forensic triage in minutes, with every finding deterministic and hashed.

Gabriel galvan
0 0
SAVVYDFIR-MCP
SAVVYDFIR-MCP

Turns Claude Code into a guardrailed DFIR investigation agent: one manifest over collected disk and memory evidence; correlates, self-corrects on contradictions, ships auditable reports.

Kismat Kunwar
2 0
AIFT (AI Forensic Triage)
AIFT (AI Forensic Triage)

AIFT is a GUI, CLI, REST API, and MCP tool that helps DFIR analysts get oriented quickly. Point it at evidence and parses artifacts with Dissect, and uses AI to turn parsed data into a traige report.

Flip Forensics
0 0
Protocol SIFT++
Protocol SIFT++

A forensically-defensible autonomous DFIR analyst: read-only by construction, adversarially self-correcting, with a tamper-evident chain of custody.

tupils1 ZHENG
1 0
SubEight
SubEight

An autonomous, self-correcting DFIR agent on SANS SIFT, leveraging LangGraph & FastMCP to triage, correlate, and produce executive reports in under 8 minutes, matching state-level threat speeds.

Lamine Gaye
3 1
SIFT-PROOF
SIFT-PROOF

A forensic investigation agent that cannot hallucinate findings — every claim is SQL-assertion-gated, chain-of-custody hashed, and replayable. Precision enforced by architecture, not by prompt.

Musoke Nestroy Nakibuuka Allen
1 0
Find Evil! — AI-Powered Incident Response Agent
Find Evil! — AI-Powered Incident Response Agent

AI‑powered agent that ingests SIEM logs, auto‑triages threats using SANS SIFT & MITRE ATT&CK frameworks, and generates professional incident reports featuring local LLM fallback for offline resilience

Donn Duinn
0 0
SIFT Sentinel — Autonomous Forensic IR Agent
SIFT Sentinel — Autonomous Forensic IR Agent

An AI agent that autonomously finds evil on a forensic disk image — driving a SIFT Workstation through

poyu tso
0 0
Sentinel Ensemble - Autonomous DFIR Ai-Agent
Sentinel Ensemble - Autonomous DFIR Ai-Agent

An autonomous DFIR agent that finds evil in under 10 minutes with a full attack timeline - calling 190+ typed tools through an MCP server, with parallel 4-AI calling and 8 workers make most efficient.

Adil Eskintan Zehra Eskintan furkan aygun edward jones + 2
2 0
EvidenceLock SIFT: Verifier-First Protocol Triage
EvidenceLock SIFT: Verifier-First Protocol Triage

Verifier-first boundary for SIFT triage: confirmed findings must prove themselves with evidence refs, tool-call logs, verifier correction, and integrity hashes.

OOYXLOO xl
0 0
Casefile
Casefile

Autonomous DFIR agent for Claude Code that verifies every finding; 0.0% hallucination.

nurusyda Nurusyda
0 0
VERDICT
VERDICT

A DFIR agent: point it at digital evidence and it returns a signed verdict — is there evil here? — with every finding citing the exact tool call, in a chain of custody you can verify offline.

Timothy Vang
0 0
Ledger
Ledger

Protocol SIFT implementation with full audit log traceability, reduced hallucinations, and improved consistency.

Matthew Long Andy Chang Dan Lyon Aaron Kuhn + 1
0 0
Evil Sift Workbench
Evil Sift Workbench

Claude Code/OpenClaw-ready DFIR triage with an MCP evidence layer that refuses hallucinated findings and treats hostile log text as data.

Theodor Engøy
0 0
VIGÍA — Forensic Intentionality Analysis System
VIGÍA — Forensic Intentionality Analysis System

"Making forensic evasion expensive — every manipulation attempt leaves a semiotic trace."

Anna Tchijova
1 0
Ojuri-Forensically Defensible AI for DFIR
Ojuri-Forensically Defensible AI for DFIR

A forensically defensible AI agent for Windows DFIR: typed read-only primitives, hash-chained audit log, separation-of-duties three-agent architecture. Verified by construction, not by prompt.

Dextan Solutions
0 0
SIFTGuard - Autonomous Forensic IR Agent
SIFTGuard - Autonomous Forensic IR Agent

Multi-agent AI that autonomously investigates endpoint compromises using SIFT forensic tools - from memory to disk to MITRE, with full audit trail and human-in-the-loop approval.

Sodiq Jimoh
1 0

73 – 96 of 118

  • «
  • 1
  • 2
  • 3
  • 4
  • 5
  • »

Devpost

  • About
  • Careers
  • Contact
  • Help

Hackathons

  • Browse hackathons
  • Explore projects
  • Host a hackathon
  • Hackathon guides

Portfolio

  • Your projects
  • Your hackathons
  • Settings

Connect

  • Twitter
  • Discord
  • Facebook
  • LinkedIn
© 2026 Devpost, Inc. All rights reserved.
  • Community guidelines
  • Security
  • CA notice
  • Privacy policy
  • Terms of service