~/f4n6 $ cat ./aidfir.md
// page

From forensic image to defensible investigative leads


STATUS: accepting two pilot engagements
LOCATION: UK · EVIDENCE EGRESS: ZERO BY DEFAULT

A fixed ten-day FindEvil pilot for incident-response teams that want to determine whether private AI can reduce forensic triage time without surrendering control of their evidence.

Give FindEvil a completed historical case whose outcome you already understand. We will measure whether it reaches the same important evidence faster—and show you where it fails.

Book a confidential scoping call hello@f4n6.co.uk →

How the pilot works

  1. Scope the case
    Select one historical, sanitised or synthetic case and agree the known findings and success criteria.
  2. Process the evidence
    FindEvil mounts the forensic image read-only, performs deterministic parsing and scoring, and creates a queryable case database.
  3. Prioritise investigative leads
    A locally hosted model performs three separate review passes to identify meaningful events, recurring signals and areas requiring analyst attention.
  4. Validate the findings
    Every material lead is checked against the parsed evidence. Unsupported conclusions and disagreements between passes are recorded.
  5. Investigate interactively
    The FindEvil CLI and forensic tools are used to query events, reconstruct activity and follow the model’s suggested lines of enquiry.
  6. Return to the evidence
    When the database is insufficient, the original mounted image remains available for conventional deep-dive forensics.

What you will learn

  • Whether FindEvil recovers the case’s known findings
  • Time taken to reach the first meaningful lead
  • Reduction from parsed events to an analyst-reviewable shortlist
  • False positives and unsupported conclusions
  • Consistency across the three review passes
  • Analyst effort required to verify each finding
  • Evidence that still requires manual examination

Deliverables

  • FindEvil analysis of the selected case
  • Prioritised, evidence-linked investigative leads
  • Interactive investigation walkthrough
  • Accuracy, consistency and failure-analysis report
  • Comparison with the original investigation outcome
  • Costed production and integration roadmap
  • Clear proceed, revise or stop recommendation

Evidence remains under your control

Testing can run on your premises or within dedicated UK-resident infrastructure. Case evidence is not submitted to public AI services, reused for model training or shared between customers.

Human judgment remains decisive

FindEvil does not declare an incident resolved or replace forensic judgment. Model outputs remain investigative hypotheses until verified against parsed artefacts or the original image.

Built by a practitioner

Jeff Davies is an experienced DFIR and incident-response consultant who has worked throughout Europe, with fifteen years in security and GIAC certifications spanning incident response, network forensics, cloud forensics and malware analysis.

Fixed engagement

From £9,500 plus any agreed travel or hardware costs.

No long-term commitment and no requirement to purchase an appliance afterward.

Discuss your historical case →