Arachnid Forensic

Arachnid Forensic

Live triage, network forensics and secure erasure — collected into a tamper-evident, signed evidence container.

Arachnid Core collects volatile system state and network evidence from a running host and seals it into a container whose every artifact is hashed, signed and chained. It is read-only against the target: the only writes go to the container directory you name.

For use by authorized analysts on systems they have permission to examine.

arachnid-core collect     -o ./ev-host01              # volatile state
arachnid-core capture     -o ./ev-net -d eth0 --duration 300 -f "not port 22"
arachnid-core parse-pcap  suspicious.pcap -o ./ev-pcap
arachnid-core verify      ./ev-host01                 # exit 0 = intact, 3 = tampered
arachnid-core report      ./ev-host01 --format html -o triage.html

arachnid-tui                                          # the same engine, from a TUI

Start here

Two things to internalize

Record the key fingerprint. Every run prints one. Without --signing-key the signing key is generated per run, so verify can prove a container is internally consistent but not who produced it. The fingerprint, recorded out-of-band, is what turns integrity into origin.

A compromised kernel lies to you. Every collector reads through OS APIs. A rootkit that hooks those APIs hides from Arachnid exactly as it hides from ps. Live triage is one input, not the answer — correlate it with a memory image.

One binary in this suite destroys data. arachnid-core, arachnid-recover and arachnid-tui are read-only against the target. arachnid-sanitize is not: it exists to make a device unreadable, and a wipe cannot be undone. It is a separate allowlisting decision and a separate habit — --dry-run first, every time.

Install

# macOS, Linux
curl -fsSL https://raw.githubusercontent.com/Team-Arachnid/forensic/main/install.sh -o install.sh
sh install.sh
# Windows
irm https://raw.githubusercontent.com/Team-Arachnid/forensic/main/install.ps1 -OutFile install.ps1
.\install.ps1

It downloads to a file rather than piping into a shell, so you can read it first (less install.sh) if you want to.

The installer verifies a signature over the digest file, then the digest of the binary, and aborts on either failure having installed nothing. Then run arachnid-cli doctor.

No release signing key has been generated yet, so the installers currently stop and say so; build from source in the meantime.

The suite

Module Status
Arachnid Core shipping — arachnid-core, arachnid-tui. Read-only
Arachnid Recover shipping — arachnid-recover, and screen 8 of the TUI. Read-only
Arachnid Sanitize shipping — arachnid-sanitize, and screen 7 of the TUI. Destroys data

Core acquires, Recover extracts, Sanitize destroys. All three share one evidence container format, so the whole chain verifies with arachnid-core verify.

Elsewhere

Licensed MIT. Version documented: 0.1.1.