March 6, 2026
DFIR Copilot by DFIRVault
An AI-augmented Splunk app that brings local, offline large-language-model (LLM) powered analysis directly into your DFIR workflows. Leverage locally hosted models like Mistral or Llama3 to query and interpret Splunk search results without sending sensitive logs to the cloud.Built by Jacob WilsonSplunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 6.x, 5.x, 4.x
Log in to rate this app
#43 in Artificial Intelligence
DFIR Copilot transforms how security analysts interact with Splunk data by integrating privacy-first LLM analysis into common DFIR and threat hunting tasks. Using a robust progressive summarization pipeline, the app maintains context when processing thousands of events and provides coherent narrative insights, anomaly explanation, and investigative suggestions — all performed locally using Ollama. - 100% local, private analysis — no outbound data required. - AI-driven insights tailored for incident response and forensic workflows. - Progressive summarization pipeline to retain context on large result sets. - Easy configuration and integration with Splunk search. Key Features & Use Cases - Conversational analysis of search results (using llmhandler). - Automated summarization for incident triage and timeline construction. - Threat hunting assistance, e.g., spotting C2 patterns or lateral movement. - Flexible prompts for custom investigation objectives. Typical use cases include: - Incident triage and executive summaries - Forensic reconstruction of attack narratives - Deep pattern detection in proxy/DNS/endpoint logs - Reducing SPL complexity with human-friendly analysis
Log in to report this app listing.