Repository navigation
First public release of Atlas, an autonomous DFIR agent. Point it at disk images, memory dumps or log exports and it runs the investigation on its own, then hands back a report in which every finding links to the tool call that produced it.
Highlights
- Investigates end to end. Triage, collection, analysis and report run as phases with no confirmation prompt between steps: disk triage, memory forensics with Volatility 3, Windows artifact parsing, super-timelines with Plaso, IOC enrichment and YARA hunting.
- Challenges its own conclusions. Five model roles share the work: an analyst drives the case, a phase director picks the next step from the evidence, an adversarial reviewer challenges every conclusion before it reaches the report, a report writer drafts it, and a run reviewer grades runs for
atlas train. - Shows its work. Every finding links to the exact tool call behind it, every answer lists its claims and evidence, and the Process view lays the whole run out in time.
- Writes the report. Answers to the case's questions, findings, indicators and a response plan, in English or German, as Markdown, HTML or PDF.
- Works with your model. Any OpenAI-compatible backend: OpenAI, a local or self-hosted server, or a gateway. Nothing is pre-selected.
- Uses your detection rules. Drop a
.yarfile intorules/and the next scan uses it. - Answers follow-up questions. Ask Atlas in the dashboard discusses the open case and runs forensic tools when it needs to.
- Ships a finished demo.
./dashboard.sh --demoopens a complete run on the public DFRWS 2005 "Rhino Hunt" challenge. No evidence and no API key needed.
Requirements
- Ubuntu 24.04 or Debian 12, on bare metal, a VM, Docker or WSL2. A SANS SIFT Workstation works too: the installer adds only what SIFT lacks.
- Python 3.11 or newer.
- At least 4 CPU cores, 8 GB RAM and 10 GB of disk for the install (8 cores and 32 GB RAM recommended), plus room for your evidence.
- An OpenAI-compatible model endpoint for your own cases. The demo needs none.
Get started
git clone https://github.com/AtlasFO/Atlas-Community.git ~/Atlas
cd ~/Atlas
./install.sh # provisions the forensic toolchain; --yes runs it unattended
./dashboard.sh --demo # serves the bundled investigations on http://127.0.0.1:8765Install walkthrough and troubleshooting: INSTALL_INSTRUCTIONS.md. Guided first run: docs/try-it-out.md. Later changes are listed in CHANGELOG.md.
License
Source-available and free for personal and evaluation use: personal use under the PolyForm Noncommercial License 1.0.0, and evaluation, at work too, for less than 32 consecutive calendar days under the PolyForm Free Trial License 1.0.0 (both in LICENSE). Any other commercial, professional or organizational use needs a separate license: dfir-systems.de.