Exterro Forensic Agent
Agentic interface on forensic analysis of live endpoints
Publisher
Exterro
Industry Type
Financial Services
Product Details
This remote digital forensics and incident response platform lets an AI client investigate live Windows endpoints through the Model Context Protocol. It runs in three tiers: a stateless MCP server exposing the tools, an Agent Hub managing WebSocket connections, and an endpoint agent installed as a Windows service, with Redis routing between them.
The MCP server registers 76 tools covering host state, filesystem, event logs, registry, browser artefacts, memory, and forensic artefact parsing. Filesystem queries use a DuckDB-backed NTFS index kept current from the USN journal, so large volumes respond in milliseconds. Collectors cover prefetch, shellbags, USB history, persistence, shadow copies, thumbcache, SAM accounts, and PowerShell history. Evidence streams as AES-encrypted, segmented archives into cloud or NAS storage with resumable jobs. Authentication uses a self-hosted OAuth 2.0 and PKCE server issuing per-user JWTs, with optional SAML SSO and tenant scoping. It deploys to GCP, AWS, and Azure, and a Google ADK agent on Vertex AI Agent Runtime connects it to Gemini with each user’s own token for attributable audit records.
Key Use Cases
Remote Live Endpoint Forensic Triage
Executes remote forensic queries across live Windows machines via an MCP server and DuckDB NTFS index, analyzing filesystem artifacts and event logs in milliseconds without interrupting end users.
Automated Evidence Packaging and Audit
Streams AES-encrypted forensic evidence packages to cloud storage while enforcing per-user JWT authentication to preserve strict chain of custody and auditability.
Explore detailed deployment path
Requires Gemini. Access integration prerequisites, specialized agent configuration guides, and implementation documentation.