Skip to main content

At Digital DNA, we develop fully automated AI pipelines that use your event logs to reconstruct adversarial AI cyber attacks on critical infrastructure.

Cyber Forensics builds practical AI that helps investigators move faster and with greater confidence—from triage and evidence capture to timeline reconstruction and reporting. Our platform preserves provenance and chain of custody, highlights the most relevant artifacts, and ties every finding back to the underlying evidence so conclusions remain defensible. Across our products, we recreate the events as they unfolded, giving teams a clear, chronological view of what happened, when it happened, and how the evidence supports it.

REMI Produces an On-the-Spot Cyber SITREP

REMI turns exported event logs into an evidence-based situation report that explains what happened, where the threat lives, what systems were touched, what to preserve, what to sandbox, what questions to ask, and what data is still needed.

Why Run a Cyber SITREP First

A cyber SITREP gives responders the first clear operating picture before they start making preservation, containment, sandboxing, or remediation decisions. Instead of beginning with assumptions or trying to preserve everything, teams can quickly understand what happened, which systems were touched, how large the incident appears to be, and what evidence matters most.

REMI helps responders prioritize the investigation early. The SITREP identifies affected accounts, devices, malware paths, scripts, processes, suspicious access, lateral movement, unresolved questions, and additional logs needed to confirm the story. That lets investigators focus first on the systems, artifacts, and evidence most likely to explain the incident.

Establish the operating picture first — quickly understand what happened, when it started, what systems were touched, and how serious the incident appears to be.
Define size and scope early — identify affected accounts, devices, networks, applications, OT systems, cloud services, or financial records before committing resources.
Avoid preserving everything blindly — focus preservation on the logs, files, devices, paths, artifacts, and records most likely to explain the incident.
Prioritize the first response actions — see what should be isolated, preserved, sandboxed, reviewed, removed, or escalated first.
See the timeline sooner — turn disconnected event logs into a sequence that shows what happened first, what followed, and what changed over time.
Connect activity across systems — link related accounts, IP addresses, sessions, files, processes, devices, vendors, and platforms that may look unrelated in separate tools.
Identify where the threat lives — surface suspicious file paths, scripts, malware artifacts, AI-spawned tools, persistence points, and affected machines.
Reduce wasted investigation time — give responders a faster path from “what happened?” to “what do we do next?” without manually reviewing every source in isolation.
Support better containment decisions — understand which systems appear affected, which are only adjacent, and which require immediate isolation or further review.
Preserve the right evidence — identify the specific logs, source records, hashes, files, scripts, sessions, and artifacts needed for forensic review or sandboxing.
Expose unresolved questions — highlight what still needs to be confirmed, including missing logs, unclear access paths, account ownership, vendor activity, or insider involvement.
Guide interviews and follow-up — generate case-specific questions for account owners, vendors, witnesses, IT teams, operators, managers, or financial staff.
Improve team alignment — give management, technical staff, investigators, and responders one evidence-backed summary instead of competing partial explanations.
Create a defensible starting point — document the evidence, confidence level, source limitations, and recommended next steps before deeper investigation begins.

What's Inside The Sitrep

A cyber SITREP gives responders the fast operational picture they need before making preservation, containment, sandboxing, or remediation decisions.

Sample REMI Cyber SITREP Excerpt

Priority Next Steps

1
Isolate affected workstation

Immediately isolate ENG-WS-04 from the network. Logs show malware-related process activity, outbound connections, and follow-on script execution from this device.

2
Preserve and sandbox suspected AI-spawned controller

Preserve C:\Users\j.martinez\AppData\Roaming\sysrunner.exe and submit a forensic copy for sandbox analysis. This artifact appears repeatedly across endpoint, process, and network evidence.

3
Remove spawned scripts and tools after preservation

After forensic preservation, remove C:\Temp\stage.ps1, C:\ProgramData\svc-loader.bat, and C:\Users\Public\update-task.vbs. These files are associated with suspicious execution and persistence behavior.

4
Review credential and token exposure

Review account activity for This email address is being protected from spambots. You need JavaScript enabled to view it., service account svc-remoteops, and VPN session source 185.77.44.201. Evidence suggests possible credential or session-token misuse.

5
Collect additional source data

Collect missing DNS logs, EDR process lineage, firewall egress records, mailbox audit logs, and VPN authentication records from 2026-07-13 08:00 UTC through 2026-07-13 11:00 UTC to expand the supported timeline.

Go From From “What Happened?” to
“What Do We Do Next?” in 10 Minutes.


A cyber SITREP gives responders a fast, evidence-backed operating picture before the investigation branches into preservation, containment, sandboxing, remediation, or interviews. Instead of starting with guesses, partial alerts, or competing explanations from different teams, REMI helps identify what happened, how large the incident appears to be, which systems were touched, and what evidence matters most.

REMI turns mixed event logs into a case-specific response view. It shows where the threat may still live, which files or scripts should be preserved, what should be sandboxed, what systems may need isolation, and what questions still need answers. It also points investigators toward the additional logs or records needed to confirm the full story.

What happened — plain-English incident summary and supported sequence of events.
Size and scope — affected accounts, devices, systems, dates, and confidence level.
Affected systems — workstations, servers, cloud accounts, OT systems, applications, or databases touched.
Threat artifacts — suspicious files, scripts, hashes, processes, malware paths, and AI-spawned tools.
Access path — phishing link, VPN session, vendor account, stolen token, endpoint activity, or insider misuse.
IP address and connection review — internal and external IPs, VPN endpoints, remote sessions, DNS lookups, geolocation clues, unusual source locations, and suspicious network connections.
Lateral movement — how activity moved between accounts, devices, networks, or platforms.
Evidence sources — logs, records, timestamps, alerts, files, sessions, and system events supporting each finding.
Priority next steps — what to isolate, preserve, sandbox, review, remove, or escalate first.
Follow-up questions — case-specific questions for investigators to ask account owners, vendors, witnesses, IT teams, operators, or managers based on the evidence REMI found.
Unresolved questions — insider involvement, vendor access, missing logs, account ownership, or additional data needed.

Partial Answer Example

REMI identified a suspicious VPN login by vendor_maint_02 from source IP 198.51.100.44 at 06:42 UTC, followed by activity on ENG-DESKTOP-07 and later access to APP-SERVER-03. The available evidence answers part of the question: the account used, the source IP, the login time, and the systems touched are known.

However, REMI cannot yet confirm whether the activity was authorized or how the access was allowed to happen. To close those gaps, REMI will ask for the MFA result, VPN session details, desktop assignment record, server ownership record, change ticket, and user/vendor activity history for the same time period.

When Connections Look Suspicious, REMI Asks the Next Questions

When REMI identifies suspicious activity, it does not stop at the first alert. It asks investigative follow-up questions, answers what it can from the available evidence, and identifies what still cannot be confirmed. For unanswered questions, REMI specifies the missing data needed to close the gap. This process turns raw findings into a SITREP-ready summary: what happened, what is connected, what is known, what is unknown, and what investigators need next.

Example

If REMI identifies a suspicious VPN login followed by activity on a server, it may already know the account used, source IP address, login time, and server reached. But it may not yet know whether the access was authorized or whether the server activity was expected.

REMI would then identify the answer gaps and request the specific missing data: MFA logs, server ownership records, change tickets, privileged-access logs, and user or vendor activity history. Once that data is added, REMI can update the SITREP with a clearer explanation of how the activity was allowed to happen.

Because Every System Tells Part of the Story. REMI Puts It Together.

REMI’s superpower is that investigators can drop in event logs from almost any vendor, platform, or system and get a unified view of what happened. Instead of reviewing firewall logs, endpoint logs, identity logs, cloud logs, VPN records, email events, and operational-system logs one at a time, REMI analyzes them together and reconstructs the incident across the full evidence set.

That unified timeline helps investigators see how the activity started, how access was achieved, which accounts and devices were involved, where lateral movement occurred, what systems were touched, and how activity crossed between different vendors and platforms. REMI turns disconnected event logs into a single forensic reconstruction report that explains the attack path, the evidence behind it, and the actions investigators should

REMI Doesn’t Just Analyze Advanced AI Cyberattacks on Critical Infrastructure. It Knows How to Investigate Them.

REMI includes six industry-specific AI pipelines, each trained to understand the forensic questions, data sources, behaviors, artifacts, timelines, and relationships that matter for that type of investigation.

Instead of forcing users to manually choose filters, queries, or workflows, REMI analyzes the evidence package, routes it through the right investigative pipeline, and generates reports tailored to the incident type, source records, and detected activity. Whether the case involves nuclear, water, electric, airport, enterprise incident response, or financial crime records, REMI applies the appropriate analysis path and turns mixed evidence into clear, defensible findings.

The result is faster reconstruction, stronger reporting, and a case-specific explanation of what happened, what evidence supports it, what remains unresolved, and what should happen next.

AI Pipeline Take Forensics Control and Delivers Results

REMI applies the right forensic methods for each scenario, analyzes logs and evidence across vendors and platforms, surfaces key artifacts, and reconstructs incident timelines in minutes. It identifies how access was achieved, which accounts, devices, files, scripts, processes, tools, and systems were involved, where lateral movement occurred, and what evidence should be preserved for deeper review.

Identifies Patterns, Behaviors That Identifies Fraud, Theft and Crimes

REMI analyzes evidence across accounts, endpoints, cloud services, VPNs, firewalls, identity systems, operational platforms, industrial environments, and enterprise networks. It surfaces unusual sign-ins, suspicious commands, file changes, configuration changes, lateral movement, repeated IPs, and relationships between users, machines, systems, and network activity.

Correlation Analysis: How Did This Happen, Who Was Involved & More

REMI connects related events across disconnected logs and evidence sources, including enterprise systems, industrial platforms, cloud records, endpoints, identity logs, network activity, financial records, access-control systems, and incident files. It builds a unified timeline showing what happened, how activity moved, which systems were touched, what remains unresolved, and what evidence supports each finding.

Comprehensive LLM Reporting

REMI turns scattered evidence into a clear, defensible investigation report. It organizes logs, notes, timelines, interviews, artifacts, and source records into a structured narrative that explains what happened, who or what was involved, which systems or records were affected, what evidence supports each finding, and what actions should be taken next.

Aggregates Your Mixed Evidence Into a Single Timeline

REMI brings together logs, user activity, system events, cloud records, endpoint data, identity records, operational tools, and vendor evidence into one unified timeline. It connects related events, repeated indicators, timestamps, accounts, devices, IPs, files, processes, commands, and configuration changes to reveal the true sequence of activity.

Local Forensics GPT Assistant

REMI includes a local, case-specific AI assistant that works from the evidence package loaded into the investigation. Investigators can ask what happened, where activity started, which systems were touched, what artifacts matter, how events relate across sources, and what evidence supports each conclusion, while keeping analysis focused on the case data.

Choose Your AI Pipeline


Airport Networks

REMI analyzes access-control logs, badge activity, camera metadata, maintenance records, vendor activity, incident reports, and airport-specific network services offline across terminal, airside, baggage, ground-operations, and restricted-facility environments. It identifies what happened, how access was achieved, which people, accounts, devices, systems, and areas were involved, and whether unauthorized access, abnormal movement, suspicious operational patterns, insider misuse, theft, sabotage, compliance violations, or safety risks affected airport operations.

Water Treatment

REMI analyzes SCADA logs, PLC and HMI activity, historian records, access-control logs, operator actions, maintenance records, vendor activity, alarms, sensor readings, and incident reports offline across treatment plants, pump stations, lift stations, reservoirs, chemical-feed systems, and distribution environments. It identifies what happened, how access was achieved, which people, accounts, devices, systems, and process areas were involved, and whether unauthorized access, abnormal control activity, suspicious operational patterns, insider misuse, sabotage, compliance violations, or public-safety risks affected water operations.

Nuclear Power

REMI analyzes SCADA logs, PLC and HMI activity, historian records, access-control logs, operator actions, maintenance records, vendor activity, alarms, sensor readings, engineering workstation activity, and incident reports offline across reactor, turbine, safety, auxiliary, security, and restricted-access environments. It identifies what happened, how access was achieved, which people, accounts, devices, systems, and plant areas were involved, and whether unauthorized access, abnormal control activity, suspicious operational patterns, insider misuse, sabotage, compliance violations, or safety risks affected nuclear operations.

Electric Grids

REMI analyzes SCADA logs, EMS/DMS activity, substation and relay records, access-control logs, operator actions, maintenance records, vendor activity, alarms, sensor readings, network telemetry, and incident reports offline across generation, transmission, distribution, substation, control-center, and field-service environments. It identifies what happened, how access was achieved, which people, accounts, devices, systems, and grid assets were involved, and whether unauthorized access, abnormal control activity, suspicious operational patterns, insider misuse, sabotage, compliance violations, or reliability and safety risks affected grid operations.

Financial Crimes

REMI analyzes bank statements, payment applications, general ledgers, QuickBooks records, NetSuite records, transaction history, account activity, vendor records, invoices, approvals, user activity, alerts, case notes, and incident reports offline across finance, accounting, payroll, procurement, vendor-management, and financial operations environments. It identifies what happened, how money moved, which people, accounts, vendors, customers, entities, transactions, systems, and approvals were involved, and whether fraud, diversion, duplicate payments, account takeover, insider misuse, synthetic identity activity, compliance violations, or suspicious financial patterns affected the organization.

Incident Response

REMI analyzes endpoint logs, EDR alerts, SIEM exports, firewall and VPN logs, identity records, email security data, cloud activity, DNS and proxy logs, file and process activity, command history, malware indicators, case notes, and incident reports offline across endpoints, servers, cloud services, user accounts, applications, networks, and security tools. It identifies what happened, how access was achieved, which people, accounts, devices, systems, files, processes, IPs, domains, and services were involved, and whether malware, credential abuse, lateral movement, persistence, exfiltration, insider misuse, policy violations, or business-impact risks affected the organization.

See Our License Options

We offer a range of licensing options designed to fit different mission requirements, operational environments, and team structures. Training and support packages are also available to ensure your personnel can deploy, use, and scale the platform effectively. From software licensing alone to full onboarding and ongoing assistance, we provide flexible options tailored to your needs.