4 Comments
User's avatar
Dom's avatar

is this like SIFT workstation from Sans Institute?

Rob T. Lee's avatar

It is. SIFT Workstation is the forensic environment, while the SIFT Protocol layers in automation and the Model Context Protocol (MCP) to allow you to execute those processes using natural language.

Sift S's avatar

OOMMGG, my name is SIFT. u gotta be kidding me...

Scott's avatar

Great Article. One thing that concerns me for DFIR jobs, is the risk (and assurances for clients) around arbitrarily sharing potentially sensitive information that may be contained in log files or other artefacts with llm providers?