Daedalus — Adaptive Artifact Handler

Community

Run only what the evidence supports.

Authorrjonhaas
Version1.0.0
Installs0

System Documentation

What problem does it solve?

Daedalus prevents wasted DFIR triage effort by ensuring analysis scripts run only when the corresponding evidence artifact is actually present, while also closing gaps when new or variant artifacts appear in a case.

Core Features & Use Cases

  • Deterministic evidence routing: Ensures phases execute based on artifact presence, avoiding irrelevant web, email, or domain work when evidence does not support it.
  • Domain extension for variants: When an artifact belongs to an existing script’s domain but isn’t covered by that script’s handler list, Daedalus extends the owning script with a new section and updates the handler registry.
  • Gap creation for new artifact types: When an artifact has no handler and no owning domain script, Daedalus generates a new SIFTics-compatible phase script, validates it, and registers it in the triage run plan.
  • ISC handoff via run plan: Produces a validated run plan for the Investigation Section Chief, which then sequences the indicated phase scripts without Daedalus executing analysis itself.

Quick Start

Ask the Investigation Section Chief to invoke Daedalus at the start of the case (after Phase 0 evidence fingerprinting) by providing the case root path and mounted evidence path, so it can return the validated run plan to execute.

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: Daedalus — Adaptive Artifact Handler
Download link: https://github.com/rjonhaas/SIFTics/archive/main.zip#daedalus-adaptive-artifact-handler

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.