Siftbench

Create a case, upload evidence, and reach your first cited finding.

Getting started

This walkthrough assumes you have access to a Siftbench workspace. Design-partner access is invite-only while we harden M7.

1. Create a case

Cases are the collaboration boundary. Give the case a name your team will recognize, set a retention class, and invite the examiners who need the evidence.

2. Upload a triage package

Drop a KAPE or Velociraptor archive — or individual artifacts — into the upload tray. Ingest hashes originals and fans parse work across the cloud parse farm.

3. Browse explorers and the timeline

When parse jobs complete, open the artifact explorers (registry, SQLite, EVTX, plist, text/hex) or the unified timeline. Evidence always renders in monospace on neutral surfaces.

4. Deploy an agent

From the case overview, start an agent run with a concrete investigative question. Agents use bounded, case-scoped tools and stream a durable transcript.

5. Triage findings

Every finding arrives with machine-resolvable citation chips. Click a chip to open the exact record. Accept or reject with your identity recorded — the API rejects findings that cannot resolve their pointers.