Show the ambition. Never disguise the roadmap as today’s product.
The approved LLD deliberately freezes V1 around a sellable Windows/ransomware investigation slice. Future evidence sources should be driven by pilot feedback and governed by ADR, security, compatibility and licensing review.
Upload → Process → Normalize → Attack Story → Ask → Proof → Confirm → Report
BASELINEProve workflow
Harden pilot
Then expand
What belongs in V1
- Windows/ransomware-oriented investigations.
- GUI case workspace, customers/tenants, assets, evidence, findings and reports.
- Resumable evidence upload, server-side hashing, immutable registration and processing status.
- OpenRelik as first forensic workflow/orchestration adapter.
- Plaso-compatible timeline parsing and Timesketch search/timeline backend.
- OCSF-aligned normalization plus forensic provenance envelope.
- Entity/relation correlation and clickable Attack Story.
- DFIQ-inspired Investigation Packs and questions.
- AI via allowlisted tools, deterministic confidence, proof-linked claims and evidence gaps.
- Proof Ledger, audit log, human validation and report generation.
- MSSP-friendly organization/customer/case hierarchy.
Do not market these as available V1 features
- Proprietary endpoint agent, disk imager or memory-acquisition agent.
- Replacement for Magnet, FTK, X-Ways or Velociraptor acquisition capability.
- Mobile forensics.
- Full cloud DFIR.
- Packet-capture analytics.
- Malware sandboxing.
- A new SIEM, SOAR or threat-intelligence platform.
- Mandatory Kubernetes deployment.
- Dedicated graph or vector database.
- Autonomous remediation or AI-triggered destructive actions.
Pilot feedback first. Developer curiosity second.
The LLD explicitly states that once the 10-minute demo path is stable, feature expansion should stop and customer demos should begin. Pilot feedback determines the next evidence source.
Additional evidence adapters
Each new adapter requires documented source/version assumptions, golden fixtures, raw-field preservation, timezone tests, provenance locators, adversarial security tests, performance benchmark, license/SBOM entry and UI/error mapping.
Cloud, mobile and acquisition integrations
These may be future directions, but the LLD does not promise dates or specific commitments. Architecture, security, license and customer demand must drive any decision.
AI action capability
Any new write/action capability for AI is an ADR trigger. Autonomous remediation remains explicitly outside the current product baseline.
“Everything else is an adapter or an Investigation Pack.”
Architecture baseline principle after the evidence-to-confirmed-finding vertical slice is proven