Skip to content

Threat Model - REVENANT

Scope

REVENANT reconstructs incident narratives from forensic artifacts. It is a read-only analytical tool operated by a DFIR analyst on evidence they are authorized to examine, in an isolated lab. It produces reports that may be used in investigations, so evidentiary integrity is the primary asset.

Assets

Asset Why it matters
Source artifacts (timelines, memory, logs) Must never be mutated by the tool
Per-event integrity hashes Prove an event was not altered post-ingest
Custody ledger Tamper-evident record of what the tool did and when
Derived narratives + confidence grades May inform legal/IR decisions; a wrong causal claim is costly

Trust boundaries

  • Source artifacts are untrusted input. They may be incomplete, contain attacker-controlled fields, or be deliberately tampered (anti-forensics).
  • The tool treats artifact-supplied timestamps as claims, not truth and cross-checks them; it never fabricates events to fill gaps.
  • The tool never writes back to source artifacts. Ingest is one-way.
  • The custody ledger is append-only and hash-chained; each record commits to the previous record's hash, so silent edits/deletions break verify().

Adversary: anti-forensics (modeled)

Technique REVENANT response
Timestomping (MFT vs $LogFile mismatch) detect_timestomp flags the event; chain confidence is penalized
Log deletion / silent gaps detect_log_gaps reports the window as unknown rather than inferring through it
Post-ingest evidence tampering verify_event / ledger verify() fail; detect_hash_mismatch flags it

Confidence is reduced, never silently absorbed: a flagged chain carries its tampering indicators into the report.

Adversary: the tool itself producing over-confident claims

  • Causal edges are explicitly labelled as rule-inferred correlations under temporal/entity constraints, not proof of intent.
  • Confidence grades are calibrated estimates derived from documented weights (confidence.WEIGHTS), surfaced in the report, and floored so a single strong signal cannot manufacture certainty.
  • Every narrative hop cites its event id, source artifact, and hash - no unsupported sentences.

Out of scope

  • Network/host compromise of the analyst workstation (assume a trusted analyst on an isolated system).
  • Cryptographic non-repudiation across organizations (the ledger is tamper-evident, not a notarized signature chain - a documented TODO).
  • Real malware handling / detonation (see SPECIMEN, a separate project).