Security Policy - REVENANT¶
Intended use¶
REVENANT is a defensive, analytical, lab-only DFIR tool. It reconstructs forensic timelines from artifacts you are authorized to analyze. It:
- reads and reconstructs artifacts; it never mutates source evidence;
- generates no offensive/exploit code and targets no third-party systems;
- ships only synthetic fixtures plus one field-trimmed public OTRF log capture (text logs, no binaries). Benchmark corpora are downloaded public event logs (OTRF Security-Datasets, EVTX-ATTACK-SAMPLES). They contain attacker command lines as text but no executable malware, and some endpoint AV products quarantine them anyway. Leave AV enabled: REVENANT records unreadable artefacts instead of failing.
Do not use it against systems or data you are not authorized to examine.
Safe defaults¶
- The core engine runs in-memory (networkx / pure-Python fallback). Neo4j, the API and PDF export are optional extras.
- Evidence XML is parsed with defusedxml (entity-expansion / XXE safe).
- The API only reads beneath
REVENANT_EVIDENCE_ROOT, refuses path traversal, and binds to127.0.0.1by default. It has no authentication: never expose it on a network. - The UI's two CDN scripts are pinned with Subresource Integrity hashes.
- The custody store is append-only (SQLite triggers), and offline edits are detected by the hash chain.
Supply-chain / CI¶
The CI workflow (.github/workflows/ci.yml) runs on every push and PR:
rufflint and the test suite on Python 3.10-3.13, plus a CLI smoke test on the real OTRF fixture;- SAST via
bandit(blocking at medium severity and above); - dependency vulnerability scan via
pip-audit; - secret scan via
gitleaks.
Reporting a vulnerability¶
This is a student/portfolio project. Please open a private GitHub security advisory or issue with reproduction steps. There is no production deployment and no SLA.
Handling real evidence¶
If you adapt REVENANT for real casework:
- Work on copies of forensic images; preserve originals with independent hashing (this tool's ledger complements, not replaces, your acquisition chain of custody).
- Keep the analysis host isolated.
- Treat all confidence grades as analyst decision support, not conclusions.