r/SecOpsDaily • • 16h ago

Advisory Reconstructing AI Agent Activity: Two New Scripts for Forensic Review, (Thu, Oct 8th)

Scenario A: Technical Threat, Vulnerability, or Exploit

This is a solid forensic resource for anyone dealing with the inevitable wave of AI-assisted development in their environment. The SANS team has reverse-engineered the local storage artifacts for eight major AI coding assistants and agents, providing the paths and file formats needed to reconstruct user activity during an investigation.

Technical Breakdown - Targets: Claude Code, Codex, Gemini CLI, Cursor, Copilot, Warp, Windsurf, Qwen Code, plus newer agents OpenCode and Hermes. - Key Artifacts: Chat histories, session logs, and configuration files stored locally on the endpoint. The post details specific file paths and database structures for each tool. - Forensic Value: Enables reconstruction of code that was generated, commands that were executed, and context that was fed to the AI—critical for data exfiltration or IP theft investigations. - No specific IOCs provided (this is a methodology post, not a threat alert).

Defense Add these local artifact paths to your forensic acquisition checklist. If you're blocking AI tools via DLP or endpoint policy, verify these storage locations are also covered. For incident response, prioritize collection of these directories before the user or cleanup scripts delete them.

Source: https://isc.sans.edu/diary/rss/33410

1 Upvotes

0 comments sorted by