Structured investigation and evidence-led inference support.
| Created | Status | Task | Result preview |
|---|---|---|---|
| pending | tsk_075e84a6eb81 id: tsk_5a02ee287436 |
||
| pending | tsk_e0e68e5bbcf3 id: tsk_34d680ee5163 |
||
| pending | You are Dolphin Investigator, the lead investigation AI for the Royal Bandits MCC Security AI Control Room.
Your role is to investigate incidents using all available evidence before reaching conclusions.
Rules:
- Never guess or invent facts.
- Build a complete timeline of events.
- Correlate logs, CCTV, AI detections, database records, user actions and system events.
- Identify the root cause.
- Highlight missing evidence.
- Assign a confidence level (Low, Medium, High).
- Recommend the next investigative actions.
- Produce a professional investigation report.
Always respond using this format:
1. Incident Summary
2. Timeline of Events
3. Evidence Reviewed
4. Findings
5. Root Cause
6. Confidence Level
7. Recommended Actions
8. Final Investigation Report
Wait for evidence before beginning an investigation. id: tsk_274a8bab3615 |
||
| pending | Hi id: tsk_d86153f0a2ea |
||
| pending | Investigate UI-TEST-001. Evidence supplied: the application became unavailable immediately after a deployment. No logs, metrics, error messages, or deployment details have been supplied. State only what the evidence supports, do not invent observations, and list the evidence required to determine root cause id: tsk_cba17690802f |
||
| pending | Investigate TEST-DOLPHIN-001. Evidence supplied: service stopped responding immediately after a configuration change. No logs, error messages, or measurements have been supplied. Determine what can actually be concluded from the evidence, and clearly state what additional evidence is needed. id: tsk_8ff033f65936 |
||
| working | research investigate locktest-1784902908 investigator id: tsk_0dea7d78dbb8 |
||
| working | Investigate missing records locktest-1784902554 id: tsk_00b1d019c15d |
||
| completed | Investigate missing records locktest-1784902463 id: tsk_9a6dba650d75 |
**Evidence Needed:** 1. **Identification of Source**: Where were the records stored? (e.g., database name, file system directory) 2. **Access Logs**: Are there any logs showing attempts to access locktest-1784902463? 3. **User Information**: Who had access rights to these records? What are their roles? 4. **Record Content**: What was the nature of the missing records? Were they textual, numerical, or binary? 5. **Deletion Timestamps**: If deletion occurred, when was it logged and by whom? **Potential Sources:** 1. **System Logs**: Server logs might contain access attempts or error messages. 2. **User Activity Reports**: These could show who accessed or modified the records around the time they went missing. **Steps to Take:** - Query system logs for any entries related to locktest-178… | |
| working | Investigate missing records locktest-1784902366 id: tsk_e19522005d4b |