DeepSIFT - A zero-hallucination autonomous DFIR agent for the SANS SIFT Workstation. 148 typed, audited, guard-railed MCP forensic tools with per-claim grounding verification, 4-axis confidence scoring, and an HMAC-signable chain of custody. .
- capability exposureinferred+35
- tool safetyinferred+25
inferred
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 13m ago · see ecosystem CVEs →
No known CVEs for this server.
- highexfiltration combocorrelate_artifacts
single tool reads + sends: fs, net
- mediumpurpose mismatchget_process_list
benign-looking name carries shell
- mediumpurpose mismatchget_command_history
benign-looking name carries shell
- mediumpurpose mismatchget_privileges
benign-looking name carries secrets
- mediumpurpose mismatchget_env_vars
benign-looking name carries shell
- mediumpurpose mismatchget_getsids
benign-looking name carries shell
- mediumpurpose mismatchget_hashdump
benign-looking name carries secrets
- mediumpurpose mismatchget_lsadump
benign-looking name carries secrets
- mediumpurpose mismatchget_cachedump
benign-looking name carries secrets
analyzed commit 2361dfd · analyzer v18 · 10h ago
skills & prompt files 2
- agent-rulesahammadshawki8-DeepSIFT-2361dfd/AGENTS.md
- agent-rulesahammadshawki8-DeepSIFT-2361dfd/CLAUDE.md
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of ahammadshawki8.