2-Day Course · Enterprises & Auditors
Capture · Preserve · Reconstruct · Prove

Agentic Forensics

Forensics and evidence for AI agents. Two days on capturing, preserving and reconstructing what an AI system did, across local, hosted and frontier models, RAG, agents, and agents that move money. You leave able to stand up a forensic capability in-house.

Why this matters now

An agent caused harm. Where is the evidence?

Autonomous agents move money, delete data and call tools with no human in the loop. When one causes harm, you have to reconstruct exactly what happened and prove it. But an agent's most important evidence, the context and reasoning behind the action, is volatile and gone the moment the process ends. You cannot investigate what nothing recorded.

You will be able to

What you can do after the course

The evidence surface

Forensics across the whole AI ecosystem

Every layer leaves different evidence, and is captured differently.

SELF-HOSTED

Local & self-hosted models

What you can capture when you run the model: prompts, outputs, the serving stack.

FRONTIER

Hosted & frontier models

Working from the gateway view when the provider runs the model.

RAG

RAG & vector stores

Retrieval evidence: what was retrieved, from where, and why.

AGENTS

Agents & MCP

Action evidence: every tool call, decision and side effect.

PAYMENTS

Agents that move money

Payment and AML evidence: receipts, sanctions checks, non-repudiation.

RECORDER

The flight recorder

Continuous, signed, tamper-evident logging so the evidence exists later.

FOR-521 -- The syllabus

Two days, from evidence to capability

Classes are custom built from the following learning modules. Instructors select ~16 hours for a 2-day delivery. Custom formats from 1 to 3 days available. (Times are approximate.)

The Forensic Problem with AI Agents

Why Traditional Forensics Breaks

40-00 Why Agents Break Traditional Forensics 1 hr

Agents make decisions, call tools, delegate and act across systems. Traditional timelines assume a human operator. What changes when the actor is autonomous.

40-01 The Agent Evidence Landscape 1 hr

Where agent evidence lives: LLM call logs, tool execution records, memory stores, delegation chains, payment receipts, model state and infrastructure telemetry.

40-02 Volatility and Time Sensitivity 0.5 hr

Agent context windows, ephemeral memory and container restarts destroy evidence fast. What to grab first and how.

40-03 Legal and Regulatory Foundations 1 hr

Chain of custody for agent evidence. Admissibility standards (UK, EU, US). What regulators expect when an AI system is involved in a breach or harm event.

Evidence Collection

Capture Across the Entire AI Stack

41-00 LLM Interaction Logs 1.5 hrs

Hands on: extract and preserve full prompt-completion histories from model serving infrastructure. Timestamps, token counts, model version and request metadata.

41-01 Tool Execution Records 1 hr

Hands on: capture MCP tool call records, function invocations and external API calls. Correlating tool calls to the prompt that triggered them.

41-02 Agent Decision Chains 1.5 hrs

Hands on: reconstruct why an agent chose a particular action. Planning traces, reasoning steps and the chain from user intent to executed action.

41-03 Memory and Context Artefacts 1 hr

Extracting vector store contents, conversation history, scratchpad state and retrieved documents. What the agent "knew" at the time of the incident.

41-04 Signed Receipts and Audit Trails 1 hr

Hands on: verify hash-chained receipt logs. Check signature validity, detect gaps or tampering, and reconstruct the sequence from the cryptographic evidence.

41-05 Infrastructure and Network Evidence 1 hr

Container logs, DNS queries, network flows and API gateway records. The infrastructure layer that corroborates or contradicts the agent-level evidence.

Timeline Reconstruction

Rebuild Exactly What Happened

42-00 Building the Agent Timeline 1.5 hrs

Hands on: merge evidence from multiple sources into a single chronological timeline. Correlate LLM calls, tool executions, payments and external interactions.

42-01 Multi-Agent Investigations 1.5 hrs

When multiple agents are involved: tracing delegation chains, identifying which agent made each decision and where authority transferred.

42-02 Counterfactual Analysis 1 hr

What should the agent have done vs what it did. Identifying the point of deviation and whether it was adversarial input, misconfiguration or model behaviour.

42-03 Attribution 1 hr

Was this the agent acting autonomously, a prompt injection, a poisoned tool response or a human using the agent as a proxy? Techniques for distinguishing the source.

Preservation and Reporting

Evidence That Holds Up

43-00 Evidence Packaging and Hashing 1 hr

Hands on: package evidence with cryptographic hashes, timestamps and chain-of-custody metadata. Evidence bundles a third party can independently verify.

43-01 The Forensic Report for AI Incidents 1.5 hrs

Report structure for agent incidents: executive summary, timeline, evidence inventory, analysis, conclusions and recommendations.

43-02 Presenting to Non-Technical Audiences 0.5 hr

Translating agent investigation findings into language a board, regulator or judge can follow.

43-03 Lessons Learned and Prevention 0.5 hr

Turning forensic findings into control improvements. Feeding back into AISVS compliance.

Building the Capability

Stand Up Agentic Forensics In-House

44-00 Agentic Forensics Playbook 1.5 hrs

Hands on: build a runbook your team can follow when an agent incident occurs. First responder actions, escalation criteria, evidence checklists and tool lists.

44-01 Tooling and Infrastructure 1 hr

What tools to deploy now so evidence exists when you need it: logging requirements, receipt infrastructure, retention policies and storage.

44-02 Training Your Incident Response Team 0.5 hr

What your IR team needs to know about agents that they do not know today. Bridging the gap between traditional IR and agentic IR.

Labs

Hands-On Investigation Labs

45-00 Evidence Collection Lab 2 hrs

A simulated agent incident. Collect evidence from LLM logs, tool records, receipts and infrastructure. Preserve it forensically. Present your findings.

45-01 Timeline Reconstruction Lab 2 hrs

Three agents, two incidents, one timeline. Merge evidence from multiple sources, identify the root cause and attribute the behaviour.

45-02 Tampered Evidence Lab 1.5 hrs

An agent audit trail has been tampered with. Detect the tampering, identify what was changed, and determine what the original evidence said.

45-03 Mock Investigation Lab 3 hrs

Full mock investigation from alert to report. Collect, preserve, analyse, reconstruct and write up. Peer review with another team.

~34 hrs
Total instructional hours
26
Individual modules across 6 sections
1-3 days
Flexible delivery, tailored to audience
Hardware-rooted evidence

AgentBee

AgentBee hardware key

AgentBee puts a hardware root of trust on an agent's most critical actions. Every approval, and every forensic seal, is signed with FIDO-grade crypto (ECDSA P-256): a tamper-evident record of who authorised what, anchored in hardware.

In forensics, that hardware root is what makes the chain of custody hold. You learn to use it.

agentbee.co.uk →
Take it home

A reference architecture for in-house forensics

You leave with a blueprint to stand up an agentic forensics capability inside your own organisation: the flight recorder, the evidence pipeline, the chain of custody, and the playbook for an agent incident. Grounded in the IETF Agent Audit Trail Internet-Draft, authored by your instructor.

Who it is for

Built for the people who investigate and assure

DFIR & incident response

Add AI agents to your investigation practice.

Auditors

Verify that agent evidence exists and holds up.

Security engineers

Build the recording and preservation into the stack.

GRC, risk & legal-tech

Govern autonomous action with evidence that survives.

Enterprise security teams

Stand up the capability in-house.

Forensic & legal experts

Extend digital forensics to autonomous agents.

Reserve a place

Build the forensics for the agentic age.

Two days, hands-on, taught by the former OWASP-AISVS Co-Leader (v1.0) qualified in cyber-forensics and author of the IETF Agent Audit Trail draft. Places are limited.

2 days intensive, hands-on For enterprises & auditors Private corporate cohorts available
Reserve a Place

Corporate & sovereign cohorts, and bespoke on-site delivery, on request.