AI Artifacts
Overview
Section titled “Overview”Evidence: AI Artifacts
Description: Inventory AI tool files (configs, transcripts, databases, MCP definitions)
Category: AI
Platform: macos
Short Name: aiart
Is Parsed: No
Sent to Investigation Hub: Yes
Collect File(s): Yes
Background
Section titled “Background”AI coding tools leave configs, transcripts, state databases, and MCP definitions under user homes and project directories such as .cursor/, .claude/, and .codex/. An inventory of those files establishes which tools were present and where their evidence lives.
Data Collected
Section titled “Data Collected”This collector gathers structured inventory data about AI tool artifacts, including path, SHA-256, size, modification time, tool name, and artifact type, and collects the matching files.
Collection Method
Section titled “Collection Method”This collector walks user homes and development directories to discover AI tool artifacts in known and project-local locations, recording file metadata without deep-parsing content.
Forensic Value
Section titled “Forensic Value”Provides a filesystem inventory of AI tool presence on the host. Paths, hashes, and timestamps support timeline correlation with other collectors and tamper detection across acquisitions.