DFIR Copilot by DFIRVault app icon

DFIR Copilot by DFIRVault

An AI-augmented Splunk app that brings local, offline large-language-model (LLM) powered analysis directly into your DFIR workflows. Leverage locally hosted models like Mistral or Llama3 to query and interpret Splunk search results without sending sensitive logs to the cloud.

Built by
splunk product badge
screenshot

Latest Version 1.0.0
March 6, 2026
Compatibility
Splunk Cloud
Platform Version: 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0, 8.2, 8.1, 8.0
CIM Version: 6.x, 5.x, 4.x
Rating

0

(0)

Log in to rate this app
Support
DFIR Copilot by DFIRVault support icon
Developer Supported app
Ranking

#38

in Artificial Intelligence
DFIR Copilot transforms how security analysts interact with Splunk data by integrating privacy-first LLM analysis into common DFIR and threat hunting tasks. Using a robust progressive summarization pipeline, the app maintains context when processing thousands of events and provides coherent narrative insights, anomaly explanation, and investigative suggestions — all performed locally using Ollama. - 100% local, private analysis — no outbound data required. - AI-driven insights tailored for incident response and forensic workflows. - Progressive summarization pipeline to retain context on large result sets. - Easy configuration and integration with Splunk search. Key Features & Use Cases - Conversational analysis of search results (using llmhandler). - Automated summarization for incident triage and timeline construction. - Threat hunting assistance, e.g., spotting C2 patterns or lateral movement. - Flexible prompts for custom investigation objectives. Typical use cases include: - Incident triage and executive summaries - Forensic reconstruction of attack narratives - Deep pattern detection in proxy/DNS/endpoint logs - Reducing SPL complexity with human-friendly analysis

Categories

Artificial Intelligence, Investigative

Created By

Jacob Wilson

Type

app

Resources

Log in to report this app listing