National Cyber Warfare Foundation (NCWF)

Inside DFIR Companion: turning investigation screenshots into AI-assisted forensic timelines


0 user ratings
2026-10-02 05:31:55
milo
Red Team (CNA)
"Inside

DFIR-Companion is a localhost forensics companion that captures authorized investigation screenshots and artifacts, then synthesizes timelines, findings, IOCs, and shareable reports with an AI vision layer you control.








Toolhasamba/DFIR-Companion — localhost AI-assisted DFIR triage server plus browser capture extension, written in TypeScript under AGPL-3.0
CategoryDigital forensics and incident response (DFIR) triage and reporting
Primary UseCorrelating artifacts and screenshots from Velociraptor, Security Onion, EDR/SIEM, and Volatility 3 into one forensic timeline with findings and IOCs
Safe UsePost-detection analysis of incidents you are authorized to investigate — internal IR engagements, lab cases, and the pre-seeded demo case
Telemetry NotePurely defensive: binds to 127.0.0.1 only, keeps evidence on local disk, and leaves no footprint on target systems; defenders observe nothing adversarial from its use

Most DFIR tooling stops at collection; the actual bottleneck is the analyst sitting between a dozen dashboards and a report deadline. DFIR-Companion, a TypeScript project from hasamba on GitHub, attacks that bottleneck directly. It is explicitly a post-detection analysis layer — the README is emphatic that it is not a detection engine — which ingests verdicts already produced by tools like Velociraptor, Security Onion, Chainsaw, Hayabusa, THOR, Cyber Triage, and generic EDR/SIEM platforms, correlates them into a single per-case forensic timeline, and synthesizes the analyst-facing outputs: findings, IOCs, attacker-path narrative, and exportable reports.


The architecture is a two-part design: a least-privilege MV3 browser extension and a local companion server. The extension captures screenshots of your investigation sessions — Velociraptor hunts, SIEM dashboards, Security Onion, Splunk4DFIR, VolWeb, VirusTotal lookups — as evidence, and the server stores them, runs what the README calls windowed AI vision analysis over them, and accumulates a per-case investigation state that feeds a live dashboard. The privacy posture is spelled out clearly: everything binds to 127.0.0.1 only, evidence stays on disk, and the AI provider is chosen by the operator rather than baked in. That local-first framing is the right default for a tool handling case evidence.


The deterministic-versus-AI split is the most interesting architectural decision in the project. Several of the heavier views — the Kill Chain bucketing by MITRE ATT&CK tactic, the Evidence Chain Graph stitching process trees and lateral movement, the attack-phase segmentation, the timeline anomaly detection, and the MITRE mitigation mapping — are derived deterministically with no AI involvement, which means no per-run cost and offline operation. The AI layer is reserved for synthesis work: executive summaries, findings generation, gap hypotheses, and remediation plan generation. An analyst who understands which panels are mechanical and which are model-generated can weight confidence accordingly, and the README makes that distinction easy to maintain.


Timeline work is clearly the center of gravity. The Super-Timeline holds every imported event before any scoping or severity filtering, acting as a superset view from which rows are promoted into the analyzed forensic timeline. The Swimlane view charts events by asset on the Y-axis and time on the X-axis, colored by severity, with a draggable time axis that filters the main timeline. Anomaly detection runs two baselines: a peer baseline that catches an asset far busier than its bucket-mates, and a self baseline that catches a normally quiet host bursting above its own typical rate — a genuinely thoughtful touch, since broad telemetry averages often mask exactly that pattern.


The IOC pipeline is where the tool earns its keep in threat-intel terms. Indicators — IPs, domains, hashes, files, processes, accounts — are enriched against VirusTotal, AbuseIPDB, and ThreatFox, with verdict badges and detection scores surfaced inline. Every detected value in an event row, including SIDs, URLs, and paths, gets a one-click quick-action tray: copy, mark benign, mark confirmed-malicious, or suggest a hunt, with each outcome recorded to the investigation log. That last detail matters for defensibility — triage decisions leave an audit trail rather than evaporating, and pinned findings travel with the case archive export.


Beacon candidate detection deserves a caveat the README itself supplies: periodic outbound channels with regular inter-arrival intervals, reported with interval, jitter, and event count, are labeled a hunting lead and not a verdict. This is the correct epistemic framing for periodicity analysis, which is notoriously prone to false positives on benign schedulers and update checkers. The login graph takes a similarly measured approach, linking accounts to hosts from super-timeline logon events and distinguishing successful, failed, and risky logons such as RDP, runas, and netonly — the classic lateral-movement signals a responder checks first.


The hypothesis-generation features are the most novel surface. Log gap analysis flags suspicious silent periods in the timeline using density and working-hours rules; the AI then proposes attacker actions that may have occurred during those windows, alongside Velociraptor collections to reconstruct the missing time. Adversary hints rank MITRE ATT&CK groups by technique overlap against the case using an offline, sub-technique-aware dataset — explicitly framed as hypothesis fuel, not attribution — and adversary emulation suggests the matched groups' tradecraft the case has not yet observed, ranked by distinctiveness, each wired to a one-click hunt expressed as Velociraptor VQL.


The mitigation bridge is what turns analysis into action. The tool maps case techniques to MITRE ATT&CK Mitigations (M-codes), ranks them by leverage — which single mitigation covers the most observed techniques — and layers MITRE D3FEND hardening, detection, and isolation steps on top, all offline. A Generate remediation plan button condenses that into a concrete incident-specific IR plan with a single AI call, and the Playbook panel maintains a remediation checklist re-synced on each synthesis run while preserving analyst status, assignee, and due dates. Key investigative questions round this out, auto-answered from the synthesized case with evidence pointers or a collect-this-next directive.


Deployment options are broad: Docker and Docker Compose, a Windows Chocolatey package, a Linux AppImage, and a portable Windows EXE that runs without Node or npm. For development the README seeds a demo case via cd companion && npm run seed-demo, with --force to overwrite and --case-id to customize. The demo — a fully pre-populated BEC and ransomware-precursor scenario with findings, IOCs, MITRE techniques, and analyst tags — loads in one click from the dashboard at http://127.0.0.1:4773/dashboard, making the tool evaluable without importing any real evidence. A hands-on lab on killercoda and a full user manual round out the documentation.


The README also documents an MCP integration path — using your own MCP servers — plus a first-run setup wizard covering AI, Presidio (presumably for PII handling in reports), enrichment providers, NSRL filtering, and notification channels, each with a live test. Capture is designed least-privilege from the start: the MV3 extension ships with zero site access at install, exact-origin console approval and revocation, and one-off active-tab capture. For a browser extension touching case evidence, that consent-per-origin model is a security decision as much as a UX one.


Caveats worth weighing before adoption: the project is small — around 21 stars at time of review — so treat it as promising rather than battle-tested, and the AGPL-3.0 license has implications if you embed it in a commercial IR platform. Every AI-derived output, from findings to gap hypotheses to group attribution hints, needs human verification before it lands in a report, and the README's own careful labeling (hunting lead, hypothesis fuel, not a verdict) suggests the author agrees. Used within its stated lane — authorized investigations where the evidence, the machines, and the AI provider are all yours — DFIR-Companion is a well-architected attempt to compress the analyst's screenshot-to-report loop.



Official project repository for hasamba/DFIR-Companion.

Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.






Source: OffensiveSec
Source Link: https://www.offsecblog.com/2026/10/inside-dfir-companion-turning.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.