π FOR-D3-END
Forensic Evidence Prioritization based on D3FEND
π Incident Scenario
Describe your security incident in natural language. When LLM (GPT-4o) is configured,
any scenario can be analyzed dynamically. Without LLM, include a known attack profile keyword (e.g., Pysilon, LockBit, APT-29, BEC) for best results.
7 attack types based on Verizon DBIR and ENISA Threat Landscape classification.
These use predefined attack profiles (DB fallback) and work without LLM API keys.
RAT/Stealer
Ransomware
APT
Insider
Supply Chain
Web Attack
Social Eng.
Analyzing incident scenario...