Keynote: SIFT: Find Evil! Defensive AI Orchestration

Keynote: SIFT: Find Evil! Defensive AI Orchestration

🎙 Rob T. Lee 👥 70K 📅 May 4, 2026 ⏱ 22 min 👁 345 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

AI orchestrationdigital forensicsSIFT workstationClaude CodeMCP

Summary

Rob T. Lee presents a keynote on integrating AI into the SIFT Workstation for defensive cybersecurity. He demonstrates how Claude Code, connected via Model Context Protocol (MCP), can automate digital forensics tasks, reducing analysis time from days to minutes. The talk covers the challenges of context rot, the importance of skill files, and the potential for AI to match the speed of offensive attacks. Lee announces a hackathon to further develop this capability, emphasizing community collaboration and open-source contributions. He highlights the urgency of adopting AI in defense due to the increasing speed of AI-driven attacks.

96 words

Critical Evaluation

Value of the Information & Strength of the Argument

The presentation provides valuable insights into the practical application of AI in digital forensics, backed by a live demonstration and the speaker’s extensive experience. The argumentation is persuasive, emphasizing the need for defenders to adopt AI to keep pace with adversaries. However, the evidence is largely anecdotal and lacks rigorous scientific validation, relying on a single case study.

Scientific Rigor, Source Quality, Title Accuracy

The talk is based on the speaker’s own testing and development, with limited external sources. The title accurately reflects the content, focusing on defensive AI orchestration. The presentation is more of an expert opinion and call to action than a peer-reviewed study, which limits its scientific rigor.

120 words

Title / Content Match

The title accurately reflects the content, which focuses on using AI orchestration for defensive purposes in digital forensics.

Quality & Reliability

7/10

The presentation is based on the speaker's direct experience and testing, providing a proof-of-concept demonstration. However, it lacks peer-reviewed evidence and detailed methodology, and the claims about AI speed advantages are anecdotal.

Key Moments

Cited Sources

  • SANS Summits — Link to upcoming SANS Summits for further learning.

Concurring Sources

  • Anthropic's report on AI threat actors — Referenced in the talk as evidence of AI-driven attacks.

Contribution & Novelties

The presentation introduces a novel proof-of-concept for using AI orchestration in digital forensics, demonstrating significant time savings. It also highlights the concept of context rot and proposes a community-driven hackathon to develop a fully weaponized defensive AI tool.

Pour aller plus loin :

  • Model Context Protocol (MCP) — Official documentation for MCP, the protocol used to integrate Claude Code with SIFT.
  • SIFT Workstation — Official page for the SIFT Workstation, an open-source digital forensics environment.
  • Claude Code — Anthropic’s AI coding assistant used in the demonstration.
  • OpenClaw — An open-source project that inspired the hackathon approach.

96 words

Radar Profile

The radar profile shows high scores in information quantity and technical level, but lower in reliability, reflecting the anecdotal nature of the evidence. The overall balance suggests a practical, hands-on presentation with strong technical content but limited scientific rigor.

Reliability 6/10

💬 No comments were provided for analysis.