Workshop · Hair on FireFind Evil! · 2026

Heads together.

Hair on fire.

The brief we set ourselves: five sections, three voices each, working toward a sharp, defensible plan. We moved through the sections in order, and beside every question each of us dropped an answer on our own colored sticky. The rule was simple — don't overthink it, capture the instinct first and refine later.

Yueviolet
Ossyblue
Shubhangyellow

Capture the instinct first, refine later.

01.Q1
The Ikigai Test

Does anyone actually want this? Who pays, who loves it, who needs it?

Yue

The SIFT workstation is already powerful; sticking strong AI LLMs like Claude on top gives us the tools to meet security threats head on.

Ossy

Pain point — keeping up with saturation and rapidly deployed threats. What we can do is build an orchestration tool that makes something like mountains of logs less overwhelming within fractions of the time it normally takes.

Shubhang

Autonomous agents now exist, but their output is basically unreadable. The moment AI starts making forensic decisions at speed, transparency stops being optional.

01.Q2
Narrowing the Scope

What is the smallest, most painful slice we can credibly own?

Yue

The investigation interface for disk image triage.

Ossy

During an active incident, analysts are dealing with raw terminal output from dozens of tools. Someone has to make sense of all that information. That's the gap.

Shubhang

Industries need an answer to agentic threats. Security teams love it, product owners need it.

01.Q3
The 'Why Now?'

What changed in the last 12 months that makes this solvable today?

Yue

How to filter and screen from all disk or logs? We focus on digital and physical footprints.

Ossy

When an invasion happened, people want to know what happened and how to find the trace of the hacker.

Shubhang

SIFT provides a rich toolkit. Combined with Google's Gemini, it assists us in unearthing the digital footprints of hacker intrusions. Take Windows for example: we can leverage Gemini to guide our usage of SIFT tools. Strings (blind scanning) pierces through the hacker's 'package deletion and renaming' camouflage, dredging up the digital DNA of Mimikatz directly from physical sectors. Contextual Analysis strips away the hacker's 'web cache' excuses, nailing down their malicious privilege escalation from the level of underlying functions. Mounting & Registry Parsing (in progress) aims to summon the official ledger of the Windows kernel, definitively locking down the hacker's precise time of crime and masquerading paths.

The plan

Land on a sharp, defensible plan.

Synthesis pending — once the stickies are placed, the team distills them into one sharp, defensible plan here.