Introducing AI Evidence Collection in Binalyze AIR
AI tools can read files, run commands, connect to external services, and retain sensitive context. Binalyze AIR gives investigators the forensic evidence to understand what happened on the computer.
The question: When an incident involves an AI-enabled computer, can your team prove what the AI saw, did, and exposed?
AI assistants have moved rapidly from experimental tools to everyday corporate software. They are used by engineering, sales, finance, legal, support, HR, and IT. To be useful, many of these tools operate close to the work: they read files, inspect projects, execute commands, call external services, and extend their capabilities through Model Context Protocol (MCP) servers, custom agents, skills, and automation hooks.
That access creates a new investigation problem. When an incident occurs, security teams may be able to see the computer, the user, and the surrounding alerts, but not the activity inside the AI tool itself. They are left asking the employee what was shared or guessing what the assistant accessed and executed.
Binalyze AIR closes that visibility gap. AI Evidence Collection acquires and analyzes forensic evidence from locally installed AI tools on Windows, macOS, and Linux endpoints, then brings it into structured, searchable views in Investigation Hub. It helps investigators move from assumptions about AI usage to evidence of what actually happened.
AI risk is not one story
Much of the conversation about AI security focuses on whether employees are allowed to use a particular tool. That is important, but it is only the starting point. Once an AI tool is present on a computer, two risk stories run in parallel.
The AI can become an execution surface
AI tools may execute shell commands with the user’s privileges, install packages, change files, or transfer data. They may also follow instructions embedded in files or web content, creating a path for indirect prompt injection. MCP servers, hooks, custom agents, skills, and permission settings extend that execution surface further. A malicious or over-privileged component can act automatically and may not look like a conventional application to the investigator.
The AI can become a channel for information exposure
Most exposure is not deliberate. An employee may paste a customer record, contract, internal report, API token, or database connection string into a prompt simply to get useful work done. The AI may also encounter sensitive information on its own while inspecting a project or troubleshooting a machine. Environment files, key material, configuration files, and credential stores can appear in commands, tool output, conversations, or local state even when the employee never intended to share them.
Those scenarios require different responses. A security team needs to know whether a user supplied a secret, the assistant produced it, a command attempted to access credential material, or a tool result brought it into the session. Without that context, teams may rotate the wrong credentials, miss the real exposure path, or struggle to explain the incident to auditors and stakeholders.
From AI artifacts to an investigation timeline
Binalyze AIR supports evidence from nine locally installed AI tools, including Claude Desktop, ChatGPT Desktop / Atlas, Gemini CLI, Claude Code, Cursor, OpenAI Codex, GitHub Copilot Chat, Continue, and Windsurf.
Eleven independently selectable AI evidence types can be collected. Together, they give investigators a view of the tools present on the computer, how those tools were configured, what activity occurred, and where risk may require closer review.
Understand the AI environment
AI Artifacts and AI Configs establish which files and tools exist, preserve hashes and timestamps, and show relevant configuration such as models, allowed tools, permission modes, and declared MCP servers.
Reconstruct what happened
AI Sessions and AI Agent Events organize prompts, assistant messages, tool calls, tool results, commands, outcomes, referenced files, and available timing information into a searchable event sequence.
Inspect the extension surface
AI MCP, AI Rules, AI Agents, AI Skills, AI Hooks, and AI Commands expose the components that shape or extend an assistant’s behavior, including remote tool servers, executable scripts, automation triggers, and broad autonomy settings.
Investigate credential exposure
AI Secrets identifies credential findings across user prompts, assistant responses, commands, tool output, and configuration values. Investigators can pivot to the relevant session and correlate the same secret across computers using a one-way fingerprint, without AIR storing the cleartext value.
Every parsed record links back to the raw source artifact from which it was derived. This allows an analyst to move from a risk flag to the session, configuration, skill, or source file that provides its investigative context, rather than treating the finding as an isolated alert.
Questions investigators can now answer
The value of AI evidence is not the number of artifacts collected. It is the quality of the questions an investigator can answer:
- Did a user paste credentials or confidential information into an AI tool on this computer?
- Did the AI itself read credential files, key material, or credential stores?
- Which credentials may require rotation, and where else did the same credential appear?
- Did the AI execute a destructive, encoded, network-transfer, or credential-reading command?
- Which MCP servers, hooks, skills, or custom agents were configured to run, and with what level of autonomy?
- Was an AI transcript altered, truncated, or reordered after the activity occurred?
Binalyze AIR also applies deterministic, offline triage signals to help analysts prioritize large volumes of activity. These signals surface patterns such as secret exposure, prompt injection phrasing, destructive commands, remote or shell-launched MCP servers, auto-executing hooks, permission-bypass settings, executable skill scripts, and broad ignore rules. A signal is a reason to review the evidence, not a verdict that a breach occurred.
Evidence that stands up to scrutiny
AI transcripts and configuration files are ordinary local artifacts. They can be changed, deleted, malformed, or partially retained. Binalyze AIR treats those limitations as part of the evidence rather than silently ignoring them.
Parsed AI events carry cryptographic hashes and a running chain that makes deleted or reordered conversation turns visible. Sessions and findings remain tied to the SHA-256 hash of their source files, while raw artifacts are preserved in the endpoint case workspace. When evidence has weaker timing or comes from a derived source, AIR records that confidence explicitly so analysts do not mistake an estimate for a precise timestamp.
The result is more than an inventory of AI-related files. It is an integrity-checked record that can support an investigation narrative, an audit, an insider or offboarding review, and post-incident reporting.
Designed with privacy in mind
Investigating AI activity can involve sensitive employee and business information. The collection approach is therefore designed to retain investigative value while limiting unnecessary exposure:
- Cleartext credentials are never stored. Findings use a masked excerpt and a one-way fingerprint.
- Full prompt and response bodies are not stored in the evidence database. Binalyze AIR retains bounded, secret-masked excerpts alongside hashes.
- MCP environment-variable names may be recorded, but their values are not.
- Command output is represented by its hash rather than retained as content.
- Triage is local, offline, and deterministic. No AI model is invoked to analyze the evidence.
Built for endpoint AI investigations
AI adoption should not mean investigating blind
Organizations will continue adopting AI because it improves how work gets done. The security response cannot be to assume every use is malicious, nor can it be to accept an evidence gap around increasingly capable endpoint software.
Binalyze AIR brings AI activity into the same evidence-led investigation discipline security teams already expect elsewhere: collect the relevant artifacts, preserve their provenance, reconstruct the activity, prioritize what matters, and let investigators reach a defensible conclusion.
When the next investigation involves an AI-enabled computer, the question should no longer be whether anyone remembers what happened. It should be what the evidence shows. With AI Evidence Collection, Binalyze AIR turns AI activity from an investigative blind spot into evidence you can examine, verify, and defend.