What problem does it solve?
Provides a structured, repeatable framework to perform open-source supply chain investigations, enabling teams to collect, correlate, and report evidence across multiple sources for defensible OSS security outcomes.
Core Features & Use Cases
- End-to-end OSS forensics workflow covering local Git history, GitHub API, Wayback Machine archives, GitHub Archive (BigQuery), and IOC enrichment.
- Phase-driven process from initialization through evidence consolidation, hypothesis formation, validation, and final reporting.
- Centralized evidence store with integrity checks and a clear chain-of-custody log to support auditable investigations.
- Pre-built templates and reporting artifacts (executive summaries, timelines, IOCs, and mitigations) for responsible disclosure and remediation.
- Guardrails and ethical guidelines to minimize intrusion and ensure redaction of secrets during investigations.
Quick Start
Launch the OSS forensics workflow against a target repository by initializing the evidence store, then run Phase 1 through Phase 6 steps to generate the final investigation report.