Sh3n0bi/NetForensicAI ? reverse-engineered prompt
Reverse engineered prompt
Build me a local first forensic investigation tool for incident response that runs on my machine and never needs a cloud backend.
I want to drop in packet captures, JSON or CSV logs, and Windows Event Logs including Sysmon, then have the app normalize everything into one clear timeline, connect related entities like IPs, domains, users, hosts, processes, and files, and show evidence based findings I can trust. It should keep every claim tied to the original evidence and event, support basic detection rules offline, map results to MITRE ATT and CK, and let me search one indicator across the whole case to see first seen, last seen, related entities, and a small relationship graph.
Please include a simple command line workflow and a local web UI, with case management, exportable reports in Markdown, JSON, and HTML, and support for live capture if possible. An optional AI helper is fine, but it must never invent citations or conclusions. If you need current docs for anything, look them up online.
Are you gonna build this?
make sure you review the code using coderabbit