evidence.jsonl
Append-only evidence records capture observations from each investigation tool call.
Open Investigator · AI DFIR reporting
Open Investigator is useful when the desired output is not just an AI summary, but a case directory with structured evidence, command audit records, JSON output, and a readable Markdown report.
Search intent
Practical workflow
Append-only evidence records capture observations from each investigation tool call.
Audited command records document what read-only checks were requested and executed.
Human-readable and structured reports summarize findings, timeline, affected components, supporting evidence, confidence, and follow-up gaps.
Common searches
The source, usage examples, contribution notes, and issue tracker live in the public Open Investigator repository.