Forensically sound AI artifact collector & analyzer. Collect evidence from 26 AI platforms, map to MITRE ATLAS, generate STIX 2.1 reports. Built for DFIR professionals.
Built for security professionals
From discovery to courtroom-ready reports. Every step verified, every artifact hashed, every timestamp UTC.
Scan endpoints for 26 AI platforms — inference engines, agent frameworks, dev tools, cloud caches, Docker AI, browser AI, and live network AI traffic. One command reveals what's running.
Read-only forensic collection with SHA-256 hashing per file. Deep mode captures session history, conversations, and credentials.
Unified timeline, IOC extraction (URLs, IPs, domains, API keys), MITRE ATLAS mapping, and risk scoring 0–100.
Generate HTML forensic reports, structured JSON, and STIX 2.1 bundles. Ingest directly into MISP, OpenCTI, or your SIEM.
15 Velociraptor VQL artifacts deploy across your fleet. Hunt for AI tools on every endpoint from a single server.
Read-only collection. SHA-256 hash verification. Chain of custody manifest. UTC timestamps. No agents, no footprints.
Prebuilt executables for macOS, Linux, and Windows (amd64 + arm64). Stdlib-only Go — cross-compiles cleanly. One-shot sweep with run: discover → deep collect → HTML + JSON reports, with full chain of custody.
Inference engines, agent frameworks, development tools, and cloud caches — TRACE finds them all.
Config, model manifests, Ed25519 signing keys, conversation DB, CLI history
Settings, LevelDB conversations, session store, model registry
chat.db (SQLite), settings.json, model cache paths
settings.yaml, chat logs, character definitions
Process detection, shell history, HuggingFace cache
Config JSON, session saves, process detection
Config, model cache, training logs, HF integration
config.yaml, proxy logs, API key store, spend tracking
Gateway config, session cache, routing rules
Sessions, state.db, memories, cron, secrets, skills, logs, auth
ai_settings.yaml, .env, workspace, file_logger
crewai.toml, .env, ChromaDB memory, knowledge base
Session state, workspace, auth tokens, command history
Agent config, session logs, tool registry, credentials
Meta-collector: correlates evidence across all other collectors
Gordon assistant, AI model registry, running AI containers/images (ollama, vLLM, LocalAI, OpenWebUI)
.aider.chat.history.md, input history, tags cache
globalStorage SQLite, .cursorrules, settings
~/.claude/ directory, projects, auth tokens
History, .sgptrc config, role definitions
Project state, session history, auth tokens
globalStorage SQLite, settings, extension state
AI framework imports, MCP server configs, hardcoded API keys in source
Model configs, refs, snapshots, auth tokens
ChatGPT, Claude, Gemini, Copilot, Perplexity, Brave Leo browser history & per-site stores
Live process→domain AI traffic classification against 100+ AI providers
Detect installed AI platforms across the system — inference engines, agents, dev tools.
Read-only forensic collection with SHA-256 hashes and chain of custody manifest.
IOC extraction, MITRE ATLAS mapping, unified timeline, risk scoring 0–100.
HTML forensic reports, structured JSON, STIX 2.1 bundles for MISP/OpenCTI.
Deploy 15 Velociraptor VQL artifacts across your entire fleet. Hunt for AI tools on every endpoint from a single server — no agent installation required.
TRACE automatically maps collected evidence to MITRE ATLAS techniques, giving you actionable threat intelligence.
TRACE calculates a composite risk score across four categories, each weighted 0–25, giving a total of 0–100.
Exposed API keys, auth tokens, .env files
URLs/domains in conversations, outbound data patterns
Prompt injection patterns, system prompt leakage
Agent frameworks, autonomous execution evidence
Install in 30 seconds. Discover AI platforms. Collect evidence. Generate reports. All forensically sound.