Skip to content
MoorAI
// digital forensics and incident response

AI agents in digital forensics

Keep case data off collection hosts and unapproved models, see every check that did not fully run, and keep a tamper-evident record of what the agent did. For DFIR teams running Claude Code, Codex and similar agents on case data. The check runs on the examiner’s machine.

Guarding every device your team works on? MoorAI for Endpoints →

// solve-it

What DFRWS asks of GenAI-assisted tools

SOLVE-IT, the open-source DFRWS knowledge base that formalises error-mitigation analysis for digital evidence (ASTM E3016-18), lists the weaknesses of GenAI-assisted tools and their mitigations. Among them:

  • Incomplete results, because the context window was exceeded or the search stopped early.
  • Inferences presented as facts: an event that did not happen, or the wrong time or place.
  • Errors with grave consequences: implicating an innocent person, or excluding an offender.

The mitigations call for guardrails that control access to data and systems, that “avoid presenting inferences as facts”, and that support transparency and reproducibility. MoorAI covers part of that, around what the agent does. It does not judge what the agent concludes.

The DFRWS post (6 October 2026) → · SOLVE-IT on GitHub →

// what moorai does

Guardrails around the agent

// console

Partial checks never read as clean

An event a check did not fully run carries a Partially evaluated label that says what was not checked: content past the scan cap, a hook error, a tool the hook does not judge. Filter the timeline to them, count them on the overview and send them to your SIEM.

// console

Rule match, inference or observation

Every alert shows its basis. Rule match: a detector or policy rule fired. Inference: a model, a score or a behaviour heuristic flagged it. Observation: a record with no verdict, such as a session summary. A model’s guess never reads as a rule match.

// action record

What the agent did, in order

Every hook run leaves a chain-stamped row on the device: the tool, the outcome, the verdict and the policy that decided it. moorai-trace replays the action chain after an incident, and moorai-verify-chain reports a deleted, reordered or edited record. The console’s governance log is hash-chained too.

// content-free signals

Signals, not case content

An enrolled device sends the console a category, a risk level and a keyed one-way hash, never the prompt, the file or the matched text. Case content stays on the examiner’s machine unless you turn on a capture tier.

// on-device dlp

Secrets and personal data stay off the model

Secrets, keys and personal data are caught before they reach a model: in prompts, in files the agent reads into its context and in MCP tool calls. On-device AI DLP

// risky actions

Download-then-run and secret uploads

A script downloaded and then run, in one command or a later one in the same session, and a secret file sent with curl, wget, nc or PowerShell, are stopped for approval by default.

// policy preset

Forensics / evidence handling, in one step

Apply it to a policy in the console and enter your evidence paths and approved model endpoints.

ControlWhat the preset sets
Collection hosts (#78, #79)Blocked: data sent to, or contact with, a public out-of-band collection host such as interactsh, Burp Collaborator or webhook.site.
Evidence pathsBlocked: a network transfer command (curl, wget, scp, sftp, rsync, rclone, nc, gsutil, azcopy, aws s3, the PowerShell web cmdlets and more) that names an evidence path you entered, or an evidence path piped into one. Up to 10 absolute paths.
Model endpointsAllow-listed: a model endpoint you have not approved is denied in shell commands, file writes, web fetches and MCP arguments.
Capture tiermetadata-plus: file paths, tool names and command shapes reach the console, never matched text or arguments. If the paths themselves are sensitive, set it back to content-free.

A preset only adds; your other rules stay. With no evidence path or no approved endpoint, that control is listed as not armed instead of reported as applied. Every apply goes into the governance log, without the paths. Enrolled devices enforce; an unenrolled device coaches.

// solve-it, row by row

Each weakness, and what MoorAI does about it

Weakness or mitigationMoorAI
Incomplete results: context window exceeded, search stopped earlyNot addressed for the agent’s analysis: MoorAI cannot see what a model left out. Its own checks follow the same rule: one that did not fully run is labelled Partially evaluated.
Incorrect inference: an event that did not occur, the wrong time or placeNot addressed. MoorAI does not check the accuracy of an AI’s forensic conclusions.
Inferences presented as factsMoorAI’s own alerts only: each says whether it is a rule match, an inference or an observation. The agent’s report is not labelled.
Wrong results with grave consequencesNot addressed. Reviewing each finding stays with the examiner.
Guardrails that control access to data and systemsIn part. Evidence-path transfers, collection hosts and unapproved model endpoints are blocked; secrets and personal data are caught before they reach a model; MCP servers can be allow-listed. Evidence cannot be made read-only by policy, and there is no path-scoped write block.
Transparency and reproducibilityIn part. A chain-stamped, on-device record of each action, its verdict and the policy behind it, and a hash-chained governance log. Content-free signals cannot be turned back into the exact command or file, and none of it proves chain of custody.
Accuracy and reliability of resultsNot addressed.
// limits

What it doesn’t do

  • It can’t make evidence read-only. There is no path-scoped write block. Mount evidence read-only or behind a write blocker.
  • It doesn’t prove chain of custody. An alert shows that a control fired, not what the evidence held or that it was unaltered.
  • Exact payloads aren’t reconstructable. Content-free signals cannot be turned back into a command or file; metadata-plus adds paths and command shapes only, and only full capture sends matched text, onto the console.
  • The on-device ledger keeps the newest 1,000 rows, pruned after 90 days by default. The console keeps every alert it receives, but an allowed call with no finding never reaches it.
  • It doesn’t check an AI’s forensic conclusions. Accuracy stays with the examiner.
  • Evidence-path matching is narrow. A copy to another directory first, a script file, an MCP tool or a path built at run time is not matched.
  • Partially evaluated calls are marked, not blocked. The hook’s own partial checks on calls with no finding stay in the on-device ledger and do not reach the console.
  • Governance, not a sandbox. MoorAI runs as the same user as the agent and fails open if its hook crashes or times out.

AI on case data,
with the checks on record.

Free and open source (MIT). It coaches with no account; enrolled, it enforces.