Connect evidence. Reconstruct events. Support review.
SURAGX is designed as an investigation-intelligence layer above established forensic acquisition and parsing tools—helping investigators organise evidence, reconstruct timelines, connect entities, test questions and inspect proof.
V1 does not replace disk imagers, memory acquisition tools or established forensic acquisition suitesExact evidence, parser and record location remain part of the provenance chain.
REVIEWABLEFrom received evidence to a reviewable case narrative.
The architecture deliberately avoids claiming that SURAGX performs the seizure or imaging itself. V1 ingests forensic evidence or derived outputs from established tools and focuses on investigation intelligence.
Phishing → credential abuse → remote movement
A synthetic investigation scenario can show how a suspicious email, endpoint activity, authentication records and remote-service events may be connected into a sequence.
Method before marketing.
Key design elements include source provenance, timestamp/timezone context, versioned parser/mapping information, proof references, contradictions, evidence gaps and an analyst review state.
Legal admissibility depends on jurisdiction, lawful acquisition, operating procedure, chain of custody, authentication, expert testimony and the specific facts of the matter. SURAGX can support reviewability; it cannot guarantee admissibility.
End-to-end provenance
Evidence ID, tool, parser, raw record locator, mapping version, hash and timestamp quality can travel with normalized events.
Attack Story
Clickable event/entity story where every node or edge is designed to expose supporting proof count.
Investigative AI with limits
Search and correlation tools are allowlisted; the model cannot use shell, arbitrary SQL or change its own case scope.
Human validation
AI-suggested findings can move through reviewing, confirmed, rejected or needs-evidence states.