UK businesses have lost £44 billion over five years to cybercrime that went undetected because evidence analysis was too slow or incomplete. Current digital forensics tools are fragmented and lack the contextual understanding to interpret evidence holistically, leaving investigations vulnerable to gaps and delays. This project builds a desktop application that automates evidence processing using generative AI and agentic techniques. It handles structured and unstructured data—emails, documents, transaction records—and combines semantic analysis, anomaly detection, and evidence-augmented retrieval to simulate investigative scenarios. If successful, the tool could cut investigation times from weeks to minutes and reduce operational costs. That matters because cybercrime and compliance failures erode trust in investigative outcomes, and many organisations lack the advanced expertise needed for robust incident response. The application is designed for both novice and expert users, bridging skill gaps that currently leave critical evidence overlooked. Beyond financial savings, faster, more reliable evidence extraction could restore stakeholder confidence in a world facing growing cyber risks. The project does not claim to solve all cybercrime—it targets the bottleneck of evidence analysis, a quiet but critical step in keeping digital infrastructure secure.
View original technical description
UK businesses have lost £44 billion over the past five years to undetected cybercrime, compliance failures, and delays in evidence analysis. Beyond the financial impact, these inefficiencies erode trust in investigative outcomes, with critical evidence often overlooked or misinterpreted. To eradicate threats and process evidence promptly, robust incident response practices are essential, but these require advanced expertise. Effective resolution depends on the precise handling of artefacts, systematic analysis, and the extraction of relevant evidence to support investigative claims. Unfortunately, current solutions rely on fragmented tools, lacking the contextual awareness needed to interpret evidence holistically, leaving investigations vulnerable to gaps and delays. This project aims to develop a desktop application that empowers investigators and security teams by automating the processing of evidence during an investigation. The application allows for the rapid identification of critical evidence across both structured and unstructured data (emails, documents, and transaction records) using GenAI-driven techniques. Designed for simplicity, it supports both novice and expert users, bridging gaps in technical expertise and accelerating investigative workflows. Built on an innovative framework that combines semantic analysis, anomaly detection, adaptive automation, and evidence-augmented retrieval, it simulates investigative scenarios to reveal high-risk insights and reduce investigation times from weeks to just minuted while significantly lowering operational costs. Beyond financial savings, it also tackles broader issues impacting individuals and society, playing a key role in restoring stakeholder trust in a world facing growing cyber risks.
Plain English summaries and category classifications on this site are generated by AI and may not perfectly reflect the original research.
Is something wrong? Let us know