What problem does it solve?
It helps you investigate suspected open-source supply-chain compromises by reconstructing what happened in a GitHub repository and producing an evidence-backed forensic report.
Core Features & Use Cases
- Evidence-first OSS forensics: A structured, multi-phase workflow focused on collecting and validating concrete indicators (commits, actors, files, and events) before making claims.
- Deleted/erased activity recovery: Uses local git analysis, GitHub API, Wayback Machine, and GitHub Archive (BigQuery) to recover or corroborate force-push and deletion indicators.
- IOC-focused investigation: Extracts and enriches IOCs (e.g., commit SHAs, workflow files, actor accounts, suspicious paths, secrets indicators) and consolidates them into a final report with a clear chain of custody.
Quick Start
Tell the agent: investigate owner/repo for supply-chain compromise and recover any deleted commits, force-push evidence, and IOCs, then generate a structured forensic report.