Skip to content

AI Artifacts

Evidence: AI Artifacts
Description: Inventory AI tool files (configs, transcripts, databases, MCP definitions)
Category: AI
Platform: windows
Short Name: aiart
Is Parsed: No
Sent to Investigation Hub: Yes
Collect File(s): Yes

AI coding tools leave configs, transcripts, state databases, and MCP definitions under user homes and project directories such as .cursor/, .claude/, and .codex/. An inventory of those files establishes which tools were present and where their evidence lives.

This collector gathers structured inventory data about AI tool artifacts, including path, SHA-256, size, modification time, tool name, and artifact type, and collects the matching files.

This collector walks user homes and development directories to discover AI tool artifacts in known and project-local locations, recording file metadata without deep-parsing content.

Provides a filesystem inventory of AI tool presence on the host. Paths, hashes, and timestamps support timeline correlation with other collectors and tamper detection across acquisitions.