Open Investigator · Local AI incident response

Use a local AI investigator for read-only server incident response.

Incident response often starts with weak clues: a strange host, a suspicious IP, a possible WebShell, a Java service anomaly, or a login that does not feel right.

Read-only toolsEvidence-backed reportFirst-pass triage
Open Investigator product mark
AI-driven server investigator: incident clues, host evidence, AI follow-up, timeline, and investigation report.

Why it matters

Use this guide when a team needs a practical first-pass server investigation workflow that keeps AI inside a read-only boundary.

Start from weak server clues instead of a fixed scanner checklist.The goal is useful technical material first, with a clear path to the open-source project when readers want to try it.
Let AI choose bounded follow-up evidence through sealed read-only tools.The goal is useful technical material first, with a clear path to the open-source project when readers want to try it.
Produce reviewable case artifacts instead of an unstructured terminal scrollback.The goal is useful technical material first, with a clear path to the open-source project when readers want to try it.

Read the source, run the CLI, and send collector or report feedback.