Getting started¶
Install¶
REVENANT is a pure-Python package (3.10–3.14). Core dependencies are pydantic and
networkx; everything else is an optional extra.
git clone https://github.com/rakshit-737/revenant
cd revenant
pip install -e . # core
pip install -e '.[evtx,api,pdf]' # raw .evtx, FastAPI UI, PDF reports
Optional extras: evtx (raw .evtx parsing), api (FastAPI + UI), pdf (WeasyPrint
reports), neo4j (live graph push), bench (benchmarks), dev (tests + ruff).
Run a built-in scenario¶
The synthetic scenarios need no data download and are the fastest way to see the output.
revenant scenarios # list scenarios
revenant demo --scenario intrusion # full phishing → PowerShell → C2 story
Analyse real artefacts¶
# OTRF/Mordor JSON lines, raw .evtx, plaso json_line/l2tcsv, a Volatility 3 dir, or auth.log
revenant analyze evidence.jsonl --format md --top 5
revenant analyze capture.evtx --format html --out report.html
revenant analyze plaso.jsonl --format json --ledger custody.sqlite
revenant verify custody.sqlite # offline hash-chain integrity check
Output formats: md, html, json, cypher. Add --pdf report.pdf (needs the pdf
extra) and --ledger custody.sqlite to persist an append-only custody ledger.
Web UI¶
pip install -e '.[api,evtx]'
REVENANT_EVIDENCE_ROOT=/path/to/evidence revenant serve
# open http://127.0.0.1:8000
The API only reads evidence, only below REVENANT_EVIDENCE_ROOT, and binds to localhost.
A pre-computed, server-less version is published as the Live demo.
Docker¶
docker run --rm -p 8000:8000 \
-v "$PWD/tests/fixtures:/evidence:ro" \
ghcr.io/rakshit-737/revenant:latest serve --host 0.0.0.0 --port 8000
Or use docker compose up api (see docker-compose.yml).
Datasets¶
Benchmarks pull public corpora with python scripts/download_data.py into $REVENANT_DATA
(default ../../datasets/revenant, outside the repo). Everything is checksum-pinned. See
Datasets.