EvidenceOps Agent

AI incident response workspace

Risk --
Confidence --
Evidence --
Response ETA --

Splunk-ready workflow

Saved searches become agent evidence, not black-box answers.

Data sources --
Tool calls --
Approval gates --

Judge proof pack

Concrete Splunk MCP and developer-tool evidence is in the repo.

Brand Portals edition

A complete brand system for the EvidenceOps product story.

Google Cloud Rapid Agent edition

Gemini turns the evidence packet into a grounded incident brief while MCP tools keep retrieval auditable.

Agent Builder flow triage -> retrieve -> brief -> approve
Gemini contract cite evidence, expose uncertainty, require approval
MCP handoff Dynatrace observability queries as callable tools

FIND EVIL terminal edition

A runnable DFIR agent validates claims, corrects overstatements, and logs every tool step.

Run path python3 agent.py evidence/oauth_token_theft_case.json
Self-correction confirmed exfiltration -> likely exfiltration
Traceability findings cite EV-001 through EV-006

Evidence Timeline

Submission Brief

draft