Book demo
Video walkthrough

Auto-IR

Automated incident response, forensics, and playbook execution

Proof

Walkthrough

Auto-IR — demo Demo

Product demo — not a live environment.

Process

How it works

  1. 1
    Scope incident

    Ingest triage output or analyst context.

  2. 2
    Forensics connect

    SSH-guided collection with playbook constraints.

  3. 3
    Playbook execution

    Ransomware, persistence, lateral movement scripts.

  4. 4
    Evidence report

    Gap table, timeline, and chain-of-custody notes.

Details

Capabilities

  • SSH forensics with guided playbooks
  • Ransomware, persistence, and lateral movement scenarios
  • Evidence chain and timeline reconstruction
  • Gap analysis when collection is incomplete

MCP tools

  • forensics_ssh_connect
  • triage_parse_email

Screenshots

Ready to see ClawDesk in action?