Skip to main content

At Digital DNA, we develop fully automated AI pipelines that use your event logs to reconstruct adversarial AI cyber attacks on critical infrastructure.

Cyber Forensics builds practical AI that helps investigators move faster and with greater confidence—from triage and evidence capture to timeline reconstruction and reporting. Our platform preserves provenance and chain of custody, highlights the most relevant artifacts, and ties every finding back to the underlying evidence so conclusions remain defensible. Across our products, we recreate the events as they unfolded, giving teams a clear, chronological view of what happened, when it happened, and how the evidence supports it.

REMI ANALYZES EVENT LOGS AND PRODUCES AN ON-THE-SPOT CYBER SITREP IN MINUTES

REMI turns exported event logs into an evidence-based situation report that explains what happened, where the threat lives, what systems were touched, what to preserve, what to sandbox, what questions to ask, and what data is still needed.

Why Run a Cyber SITREP First

A cyber SITREP gives responders the first clear operating picture before they start making preservation, containment, sandboxing, or remediation decisions. Instead of beginning with assumptions or trying to preserve everything, teams can quickly understand what happened, which systems were touched, how large the incident appears to be, and what evidence matters most.

REMI helps responders prioritize the investigation early. The SITREP identifies affected accounts, devices, malware paths, scripts, processes, suspicious access, lateral movement, unresolved questions, and additional logs needed to confirm the story. That lets investigators focus first on the systems, artifacts, and evidence most likely to explain the incident.

Establish the operating picture first — quickly understand what happened, when it started, what systems were touched, and how serious the incident appears to be.
Define size and scope early — identify affected accounts, devices, networks, applications, OT systems, cloud services, or financial records before committing resources.
Avoid preserving everything blindly — focus preservation on the logs, files, devices, paths, artifacts, and records most likely to explain the incident.
Prioritize the first response actions — see what should be isolated, preserved, sandboxed, reviewed, removed, or escalated first.
See the timeline sooner — turn disconnected event logs into a sequence that shows what happened first, what followed, and what changed over time.
Connect activity across systems — link related accounts, IP addresses, sessions, files, processes, devices, vendors, and platforms that may look unrelated in separate tools.
Identify where the threat lives — surface suspicious file paths, scripts, malware artifacts, AI-spawned tools, persistence points, and affected machines.
Reduce wasted investigation time — give responders a faster path from “what happened?” to “what do we do next?” without manually reviewing every source in isolation.
Support better containment decisions — understand which systems appear affected, which are only adjacent, and which require immediate isolation or further review.
Preserve the right evidence — identify the specific logs, source records, hashes, files, scripts, sessions, and artifacts needed for forensic review or sandboxing.
Expose unresolved questions — highlight what still needs to be confirmed, including missing logs, unclear access paths, account ownership, vendor activity, or insider involvement.
Guide interviews and follow-up — generate case-specific questions for account owners, vendors, witnesses, IT teams, operators, managers, or financial staff.
Improve team alignment — give management, technical staff, investigators, and responders one evidence-backed summary instead of competing partial explanations.
Create a defensible starting point — document the evidence, confidence level, source limitations, and recommended next steps before deeper investigation begins.

Go From From “What Happened?” to
“What Do We Do Next?” in 10 Minutes.


A cyber SITREP gives responders a fast, evidence-backed operating picture before the investigation branches into preservation, containment, sandboxing, remediation, or interviews. Instead of starting with guesses, partial alerts, or competing explanations from different teams, REMI helps identify what happened, how large the incident appears to be, which systems were touched, and what evidence matters most.

REMI turns mixed event logs into a case-specific response view. It shows where the threat may still live, which files or scripts should be preserved, what should be sandboxed, what systems may need isolation, and what questions still need answers. It also points investigators toward the additional logs or records needed to confirm the full story.

Know What Happened, What Was Touched, Who Was Involved, What Changed, What To Ask, and What To Do Next

What happened — plain-English incident summary and supported sequence of events.
Size and scope — affected accounts, devices, systems, dates, and confidence level.
Affected systems — workstations, servers, cloud accounts, OT systems, applications, or databases touched.
Threat artifacts — suspicious files, scripts, hashes, processes, malware paths, and AI-spawned tools.
Access path — phishing link, VPN session, vendor account, stolen token, endpoint activity, or insider misuse.
IP address and connection review — internal and external IPs, VPN endpoints, remote sessions, DNS lookups, geolocation clues, unusual source locations, and suspicious network connections.
Lateral movement — how activity moved between accounts, devices, networks, or platforms.
Evidence sources — logs, records, timestamps, alerts, files, sessions, and system events supporting each finding.
Priority next steps — what to isolate, preserve, sandbox, review, remove, or escalate first.
Follow-up questions — case-specific questions for investigators to ask account owners, vendors, witnesses, IT teams, operators, or managers based on the evidence REMI found.
Unresolved questions — insider involvement, vendor access, missing logs, account ownership, or additional data needed.

What's Inside The SitRep

A cyber SITREP gives responders the fast operational picture they need before making preservation, containment, sandboxing, or remediation decisions.

Next Steps

Sample REMI Cyber SITREP Excerpt

Priority Next Steps

1
Isolate affected workstation

Immediately isolate ENG-WS-04 from the network. Logs show malware-related process activity, outbound connections, and follow-on script execution from this device.

2
Preserve and sandbox suspected AI-spawned controller

Preserve C:\Users\j.martinez\AppData\Roaming\sysrunner.exe and submit a forensic copy for sandbox analysis. This artifact appears repeatedly across endpoint, process, and network evidence.

3
Remove spawned scripts and tools after preservation

After forensic preservation, remove C:\Temp\stage.ps1, C:\ProgramData\svc-loader.bat, and C:\Users\Public\update-task.vbs. These files are associated with suspicious execution and persistence behavior.

4
Review credential and token exposure

Review account activity for This email address is being protected from spambots. You need JavaScript enabled to view it., service account svc-remoteops, and VPN session source 185.77.44.201. Evidence indicates credential or session-token misuse must be reviewed.

5
Collect additional source data

Collect DNS logs, EDR process lineage, firewall egress records, mailbox audit logs, and VPN authentication records from 2026-07-13 08:00 UTC through 2026-07-13 11:00 UTC to expand the supported timeline.

Follow Up Questions

Partly answered: REMI confirmed the VPN session used vendor_maint_02 outside the normal access window.
Question: Was the VPN login approved?
Event logs needed: Maintenance ticket, vendor work order, change approval, and MFA approval record.
Partly answered: REMI confirmed the VPN login came from 203.0.113.44, a source IP not seen in prior sessions.
Question: Was this source location expected?
Event logs needed: VPN source-IP history, identity sign-in logs, geolocation records, and vendor access baseline.
Answered: REMI confirmed the session reached 192.165.43.18 after authentication.
Detail gap: Was this an approved intermediate host?
Event logs needed: Asset inventory, firewall flow logs, DHCP/DNS records, system owner records, and approved remote-access path records.
Partly answered: REMI connected the VPN session to traffic toward ENG-WS-04.
Question: Which engineering actions were performed?
Event logs needed: EDR telemetry, engineering workstation logs, project-file access records, tool execution logs, and jump-host records.
Open question: The account owner behind the VPN session is not fully proven.
Question: Who used the VPN account?
Event logs needed: MFA device record, identity provider logs, account-owner record, vendor assignment record, and privileged-access logs.

Reconstruction

Attack activity appears across real systems
VPN, identity, firewall, endpoint, engineering, HMI, historian, vendor, and plant-support records each capture part of the incident.
Those systems create event logs
Each touched system records account use, source IPs, session times, destination systems, commands, file activity, alarms, configuration changes, and support records.
The event logs enter REMI
REMI analyzes the copied evidence package offline and uses the records to reconstruct the incident sequence across systems.
REMI connects records across sources
REMI links the VPN login, source IP, account, workstation activity, firewall flows, engineering records, HMI activity, historian events, and vendor access into one evidence-backed sequence.
Correlation shows what connected to what
The correlation phase shows which records line up by account, device, IP address, timestamp, destination system, session window, file path, process, or configuration change.
Analysis explains how it happened
After correlation, REMI explains how access was achieved, how activity moved, why alerts did not escalate sooner, which systems were touched, and what evidence supports the explanation.
The SITREP turns findings into action
The output gives responders the size and scope, affected systems, confirmed findings, unresolved questions, records still needed, preservation targets, sandbox items, removal steps, and verification actions.

REMI Doesn’t Just Analyze Advanced AI Cyberattacks on Critical Infrastructure. It Knows How to Investigate Them.

Because Every System Tells Part of the Story. REMI Puts It Together.

REMI’s superpower is that investigators can drop in event logs from almost any vendor, platform, or system and get a unified view of what happened. Instead of reviewing firewall logs, endpoint logs, identity logs, cloud logs, VPN records, email events, and operational-system logs one at a time, REMI analyzes them together and reconstructs the incident across the full evidence set.

That unified timeline helps investigators see how the activity started, how access was achieved, which accounts and devices were involved, where lateral movement occurred, what systems were touched, and how activity crossed between different vendors and platforms. REMI turns disconnected event logs into a single forensic reconstruction report that explains the attack path, the evidence behind it, and the actions investigators should

REMI includes six industry-specific AI pipelines, each trained to understand the forensic questions, data sources, behaviors, artifacts, timelines, and relationships that matter for that type of investigation.

Instead of forcing users to manually choose filters, queries, or workflows, REMI analyzes the evidence package, routes it through the right investigative pipeline, and generates reports tailored to the incident type, source records, and detected activity. Whether the case involves nuclear, water, electric, airport, enterprise incident response, or financial crime records, REMI applies the appropriate analysis path and turns mixed evidence into clear, defensible findings.

The result is faster reconstruction, stronger reporting, and a case-specific explanation of what happened, what evidence supports it, what remains unresolved, and what should happen next.

Your Portable Cyber Wing-Man that thinks like an investigator

AI Pipeline Take Forensics Control and Delivers Results

REMI applies the right forensic methods for each scenario, analyzes logs and evidence across vendors and platforms, surfaces key artifacts, and reconstructs incident timelines in minutes. It identifies how access was achieved, which accounts, devices, files, scripts, processes, tools, and systems were involved, where lateral movement occurred, and what evidence should be preserved for deeper review.

Identifies Patterns, Behaviors That Identifies Fraud, Theft and Crimes

REMI analyzes evidence across accounts, endpoints, cloud services, VPNs, firewalls, identity systems, operational platforms, industrial environments, and enterprise networks. It surfaces unusual sign-ins, suspicious commands, file changes, configuration changes, lateral movement, repeated IPs, and relationships between users, machines, systems, and network activity.

Correlation Analysis: How Did This Happen, Who Was Involved & More

REMI connects related events across disconnected logs and evidence sources, including enterprise systems, industrial platforms, cloud records, endpoints, identity logs, network activity, financial records, access-control systems, and incident files. It builds a unified timeline showing what happened, how activity moved, which systems were touched, what remains unresolved, and what evidence supports each finding.

Comprehensive LLM Reporting

REMI turns scattered evidence into a clear, defensible investigation report. It organizes logs, notes, timelines, interviews, artifacts, and source records into a structured narrative that explains what happened, who or what was involved, which systems or records were affected, what evidence supports each finding, and what actions should be taken next.

Aggregates Your Mixed Evidence Into a Single Timeline

REMI brings together logs, user activity, system events, cloud records, endpoint data, identity records, operational tools, and vendor evidence into one unified timeline. It connects related events, repeated indicators, timestamps, accounts, devices, IPs, files, processes, commands, and configuration changes to reveal the true sequence of activity.

Local IP Lookup

REMI’s local IP lookup scans the case evidence for IP addresses, removes duplicates, separates private/internal addresses from public ones, and enriches the remaining public IPs with flagged-connection, geolocation, ASN, hosting, domain-history, and source-record context. Investigators can see which IPs appeared in the case, where they resolved, which accounts or devices touched them, and which records support the connection.

Choose Your AI Pipeline


Airport Networks

REMI analyzes access-control logs, badge activity, camera metadata, maintenance records, vendor activity, incident reports, and airport-specific network services offline across terminal, airside, baggage, ground-operations, and restricted-facility environments. It identifies what happened, how access was achieved, which people, accounts, devices, systems, and areas were involved, and whether unauthorized access, abnormal movement, suspicious operational patterns, insider misuse, theft, sabotage, compliance violations, or safety risks affected airport operations.

Water Treatment

REMI analyzes SCADA logs, PLC and HMI activity, historian records, access-control logs, operator actions, maintenance records, vendor activity, alarms, sensor readings, and incident reports offline across treatment plants, pump stations, lift stations, reservoirs, chemical-feed systems, and distribution environments. It identifies what happened, how access was achieved, which people, accounts, devices, systems, and process areas were involved, and whether unauthorized access, abnormal control activity, suspicious operational patterns, insider misuse, sabotage, compliance violations, or public-safety risks affected water operations.

Nuclear Power

REMI analyzes SCADA logs, PLC and HMI activity, historian records, access-control logs, operator actions, maintenance records, vendor activity, alarms, sensor readings, engineering workstation activity, and incident reports offline across reactor, turbine, safety, auxiliary, security, and restricted-access environments. It identifies what happened, how access was achieved, which people, accounts, devices, systems, and plant areas were involved, and whether unauthorized access, abnormal control activity, suspicious operational patterns, insider misuse, sabotage, compliance violations, or safety risks affected nuclear operations.

Electric Grids

REMI analyzes SCADA logs, EMS/DMS activity, substation and relay records, access-control logs, operator actions, maintenance records, vendor activity, alarms, sensor readings, network telemetry, and incident reports offline across generation, transmission, distribution, substation, control-center, and field-service environments. It identifies what happened, how access was achieved, which people, accounts, devices, systems, and grid assets were involved, and whether unauthorized access, abnormal control activity, suspicious operational patterns, insider misuse, sabotage, compliance violations, or reliability and safety risks affected grid operations.

Financial Crimes

REMI analyzes bank statements, payment applications, general ledgers, QuickBooks records, NetSuite records, transaction history, account activity, vendor records, invoices, approvals, user activity, alerts, case notes, and incident reports offline across finance, accounting, payroll, procurement, vendor-management, and financial operations environments. It identifies what happened, how money moved, which people, accounts, vendors, customers, entities, transactions, systems, and approvals were involved, and whether fraud, diversion, duplicate payments, account takeover, insider misuse, synthetic identity activity, compliance violations, or suspicious financial patterns affected the organization.

Incident Response

REMI analyzes endpoint logs, EDR alerts, SIEM exports, firewall and VPN logs, identity records, email security data, cloud activity, DNS and proxy logs, file and process activity, command history, malware indicators, case notes, and incident reports offline across endpoints, servers, cloud services, user accounts, applications, networks, and security tools. It identifies what happened, how access was achieved, which people, accounts, devices, systems, files, processes, IPs, domains, and services were involved, and whether malware, credential abuse, lateral movement, persistence, exfiltration, insider misuse, policy violations, or business-impact risks affected the organization.

See Our License Options

We offer a range of licensing options designed to fit different mission requirements, operational environments, and team structures. Training and support packages are also available to ensure your personnel can deploy, use, and scale the platform effectively. From software licensing alone to full onboarding and ongoing assistance, we provide flexible options tailored to your needs.